UNKNOWN (0.0)
    Plugin

    Stored Cross-Site Scripting in DA Media GigList Plugin via Shortcode

    Published Date: 3/7/2026
    CVE ID: CVE-2026-1805

    Summary

    The DA Media GigList plugin for WordPress, in versions up to 1.9.0, is subject to a stored cross-site scripting vulnerability. This flaw allows authenticated users with contributor or higher roles to inject harmful scripts through the damedia_giglist shortcode, potentially affecting other users accessing compromised pages.

    Vulnerability Details

    The vulnerability arises from inadequate input sanitization and output escaping mechanisms in the DA Media GigList plugin when handling attributes of the damedia_giglist shortcode. Contributors or users with elevated permissions can exploit this flaw by submitting crafted input that leads to the execution of arbitrary web scripts. This type of stored XSS attack can have severe implications, as it allows the persistent delivery of malicious code, which will execute for every visitor to the affected pages, including administrators. Such scripts could lead to session hijacking or data theft, effectively compromising the site's security posture. Cross-site scripting in this case is particularly concerning due to the persistent nature of the threat, as it remains embedded within the webpage and doesn't require continuous user interaction to remain active.

    Recommendations

    To mitigate this vulnerability, it is essential to restrict contributor and editor-level permissions, thereby limiting their capability to insert shortcodes until a patch is applied. Utilize a Web Application Firewall (WAF) to catch and block malicious scripts from being executed. Additionally, ensure all user inputs are duly sanitized, and output is properly escaped to deter script injections.

    Available Fixes

    Last Updated: 3/10/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More