Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings. | |
| Title | Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-13T20:06:35.886Z
Reserved: 2026-09-03T08:38:57.540Z
Link: CVE-2026-85129
No data.
Status : Received
Published: 2026-09-13T21:17:02.063
Modified: 2026-09-13T21:17:02.063
Link: CVE-2026-85129
No data.
OpenCVE Enrichment
No data.
No weakness.