CVE-2026-4120Disclosure

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter within the Info Cards block in all versions up to, and including, 2.0.7. This is due to insufficient input validation on URL schemes, specifically the lack of javascript: protocol filtering. The block's render.php passes all attributes as JSON to the frontend via a data-attributes HTML attribute using esc_attr(wp_json_encode()), which prevents HTML attribute injection but does not validate URL protocols within the JSON data. The client-side view.js then renders the btnUrl value directly as an href attribute on anchor elements without any protocol sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject javascript: URLs that execute arbitrary web scripts when a user clicks the rendered button link.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-23: 103-1903-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4120 The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter within the Info Cards b… https://www.cve.org/CVERecord?id=CVE-2026-4120

    Post summary

    The text announces that the Info Cards WordPress plugin is affected by a stored XSS vulnerability via the btnUrl parameter, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000141
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4120 Stored XSS in WordPress Info Cards Plugin via Unsanitized 'btnUrl' Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4120

    Post summary

    The text announces a stored XSS vulnerability in the WordPress Info Cards Plugin via an unsanitized 'btnUrl' parameter, providing technical details but no PoC, exploitation evidence, or patch information.

    0000034
    4.0K followersView on X

Explore more