CVE-2026-3876Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by submitting a comment containing a crafted 'prismatic_encoded' pseudo-shortcode.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-16); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-16: 3Mentions · 2026-04-24: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-24: 104-1604-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-163
Disclosure3
2026-04-241
Patch1
Full discourse4 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2026-3876 (CVSS 7.2) Prismatic WordPress plugin ≤3.7.3 vulnerable to Stored XSS via prismatic_encoded shortcode. Unauthenticated attackers can inject malicious scripts through comments. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/xEcsA1zKxu

    Post summary

    The post announces a stored‑XSS flaw (CVE‑2026‑3876) in Prismatic WordPress plugin (≤3.7.3) with a CVSS of 7.2, and urges users to apply the patch immediately.

    0000066
    26 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3876 Stored Cross-Site Scripting in Prismatic Plugin for WordPr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3876 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A short tweet links to CVE‑2026‑3876 details, noting a stored XSS flaw in the Prismatic WordPress plugin, but contains no PoC, exploit code, active‑exploitation claim, or patch information.

    0000034
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3876 The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3… https://www.cve.org/CVERecord?id=CVE-2026-3876

    Post summary

    The post announces CVE-2026-3876, a stored XSS flaw in the Prismatic WordPress plugin affecting versions up to 3.7.3, and provides a link to the official CVE record.

    0000038
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-3876 The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shor… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-3876 #WordPress #CyberSecurity #InfoSec

    Post summary

    CVE-2026-3876 is a stored XSS vulnerability in the Prismatic plugin for WordPress with a CVSS score of 7.2, disclosed with technical details.

    000002
    145 followersView on X

Explore more