CVE-2026-10091Disclosure

MEDIUMCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-24: 1Mentions · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-26: 1Exploit Tool / Code · 2026-06-26: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-26: 106-2406-26
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-241
Disclosure1
2026-06-261
PoC1
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-10091-email-javascript-cloaker-version-1-03-high-vulnerability-proof-of-concept CVE-2026-10091 email-javascript-cloaker (CVSS Score 7.2) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wps

    Post summary

    A proof‑of‑concept for the high‑severity CVE‑2026‑10091 WordPress plugin vulnerability has been shared, with details of the flaw and its CVSS score.

    0000045
    11 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-10091 (CVSS 7.2) - Email JavaScript Cloak WordPress plugin vulnerable to Stored XSS. All versions ≤1.03 affected. Authenticated attackers (contributor+) can inject malicious scripts. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/jHZqFHVx27

    Post summary

    CVE‑2026‑10091 is disclosed as a Stored XSS in the Email JavaScript Cloak WordPress plugin, affecting all versions up to 1.03 with a CVSS score of 7.2; users are advised to patch immediately.

    0000033
    50 followersView on X

Explore more