UNKNOWN (0.0)
    Plugin

    Stored Cross-Site Scripting in Infomaniak Connect for OpenID WordPress Plugin

    Published Date: 3/7/2026
    CVE ID: CVE-2026-1824

    Summary

    The Infomaniak Connect for OpenID plugin is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 1.0.2. An attacker with Contributor-level access or higher can inject malicious scripts via the 'endpoint_login' parameter in the infomaniak_connect_generic_auth_url shortcode.

    Vulnerability Details

    The vulnerability exists in the Infomaniak Connect for OpenID plugin due to a lack of proper input sanitization and output escaping on the 'endpoint_login' parameter of the infomaniak_connect_generic_auth_url shortcode. This oversight allows authenticated users with at least Contributor-level access to inject arbitrary JavaScript code into posts or pages. When these pages are viewed, the scripts execute in the context of the viewing user's browser, potentially leading to session hijacking, defacement, or distribution of malicious content. The core issue arises from the failure to adequately restrict and cleanse user inputs before they are stored and later rendered on web pages. This type of vulnerability is particularly dangerous because it persists within the site content until explicitly removed, potentially affecting multiple users who view the content.

    Recommendations

    To mitigate this vulnerability, restrict access to the plugin to only trusted users by elevating the required user role for plugin usage. Implement full input validation and output encoding practices in the plugin code. Regularly review user roles and capabilities to ensure minimal access is granted where necessary. Performing a site-wide security audit can also help identify and remediate any other potential vulnerabilities.

    Available Fixes

    Last Updated: 3/10/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More