CVE-2026-2602Disclosure

MEDIUMCVSS 6.4 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-29); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-29: 3Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-31: 1Active Exploitation · 2026-03-30: 1Technical Details · 2026-03-29: 2Technical Details · 2026-03-31: 103-2903-3003-31
Signal classification4 categories
Disclosure
240.0%
General
120.0%
Active Exploitation
120.0%
PoC
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-293
Disclosure2General1
2026-03-301
Active Exploitation1
2026-03-311
PoC1
Full discourse5 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-2602-twentig-version-1-9-7-medium-vulnerability-proof-of-concept CVE-2026-2602 #WordPress plugin #vulnerability twentig https://atomicedge.io/?p=6567 #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post references a proof‑of‑concept for CVE‑2026‑2602 affecting WordPress Twentig 1.9.7 with a medium severity rating, but does not provide exploit code, active attacks, or patch information.

    0001055
    5 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Twentig Supercharged Block Editor Plugin (CVE-2026-2602) https://vuldb.com/vuln/354104/cti

    Post summary

    The text indicates that attacker activity toward the Twentig Supercharged Block Editor Plugin (CVE‑2026‑2602) has increased, suggesting ongoing exploitation in the wild.

    0000083
    2.1K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2602 📊 Severity: 6.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2602 #CVE-2026-2602 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/ekXLKJFA38

    Post summary

    The tweet announces a newly listed CVE-2026-2602 affecting WordPress, noting its severity, but provides no technical details, PoC, or exploit information.

    0000032
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2602 The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to … https://www.cve.org/CVERecord?id=CVE-2026-2602

    Post summary

    The Twentig WordPress plugin is disclosed to have a stored XSS flaw in versions up to 1.9.7 via the featuredImageSizeWidth parameter, as recorded in CVE-2026-2602.

    0000059
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2602 - Twentig <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' Intel Report: https://ift.tt/zS5YHtd

    Post summary

    Alert identifies CVE-2026-2602 as an authenticated stored XSS vulnerability in Twentig theme up to 1.9.7, affecting Contributor+ users through the 'featuredImageSizeWidth' field.

    0000022
    280 followersView on X

Explore more