๐Ÿ” CVE Alert

CVE-2026-92424

UNKNOWN 0.0

Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.

Vendor unknown
Product content egg
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown content egg

Be the first to know when new unknown vulnerabilities affecting unknown content egg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Content Egg
0 < 11.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/917b8042-b38c-4b6a-9237-1dd08ada157d/

Credits

aymen benlamari WPScan