CVE-2026-9677Disclosure

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-27: 3Technical Details · 2026-06-27: 306-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-9677 The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML … https://www.cve.org/CVERecord?id=CVE-2026-9677

    Post summary

    The post discloses that the Shariff plugin version 1.0.11 contains an unsanitized input vulnerability (CVE‑2026‑9677) but provides no proof of concept, exploit code, or patch details.

    00020720
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9677 The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML … https://www.cve.org/CVERecord?id=CVE-2026-9677 ----- Traducción: CVE-2026-9677 El … http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑9677, noting a lack of input sanitization in the Shariff for WordPress plugin that could lead to XSS issues.

    0001031
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9677 Stored Cross-Site Scripting in Shariff for WordPress Plugin Through 1.0.11 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9677

    Post summary

    The text announces a stored XSS vulnerability (CVE‑2026‑9677) in the Shariff WordPress plugin (up to v1.0.11), without discussing PoC, exploitation, patching, or mitigation details.

    00010131
    4.1K followersView on X

Explore more