🔐 CVE Alert

CVE-2026-88788

UNKNOWN 0.0

Text Styler <= 1.1.1 - Contributor+ Stored XSS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.

Vendor unknown
Product text styler
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown text styler

Be the first to know when new unknown vulnerabilities affecting unknown text styler are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Text Styler
0 ≤ 1.1.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/6175fc16-960b-4dbe-bda2-21b4ce7de54b/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan