CVE-2026-3368Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and including 1.2.9. This is due to insufficient input sanitization in the sanitize_ig_data() function which only sanitizes array values but not array keys, combined with missing output escaping in the ig_settings.php template where stored parameter keys are echoed directly into HTML. When a request is made to the site, the plugin captures the query string via $_SERVER['QUERY_STRING'], applies esc_url_raw() (which preserves URL-encoded special characters like %22, %3E, %3C), then passes it to parse_str() which URL-decodes the string, resulting in decoded HTML/JavaScript in the array keys. These keys are stored via update_option('ig_requests_log') and later rendered without esc_html() or esc_attr() on the admin log page. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in the admin log page that execute whenever an administrator views the Injection Guard log interface.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-22: 1Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 103-2103-22
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-03-221
Patch1
Full discourse3 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 WordPress Users Alert! 🚨 The Injection Guard plugin (up to v1.2.9) is vulnerable to Stored XSS through query parameters, risking admin accounts! 🛡️ 👉 Update immediately or restrict access! More info here: https://www.tenable.com/cve/CVE-2026-3368 #CyberSecurity #WordPress #XSS

    Post summary

    WordPress users are warned of a stored XSS vulnerability in the Injection Guard plugin (up to v1.2.9) and urged to update immediately or restrict access to mitigate the risk to admin accounts.

    0000031
    259 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3368 The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and including 1.2.9. Thi… https://www.cve.org/CVERecord?id=CVE-2026-3368

    Post summary

    The CVE-2026-3368 listing details a stored XSS flaw in the Injection Guard WordPress plugin, affecting all versions up to 1.2.9 via malicious query parameter names. No PoC, exploit code, active exploitation, or patch information is provided.

    0000092
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3368 - fahadmahmood - Injection Guard - https://www.redpacketsecurity.com/cve-alert-cve-2026-3368-fahadmahmood-injection-guard/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3368 #fahadmahmood #injection-guard

    Post summary

    The tweet links to a CVE alert from Red Packet Security, indicating a disclosure of a new vulnerability, but contains no PoC, exploit, active usage, patch, or technical detail.

    0000078
    3.6K followersView on X

Explore more