Back

MEDIUM

Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link

Published Aug 12, 2026

Description

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 12, 2026
Updated Aug 12, 2026
Reserved Jul 9, 2026
CISA Vulnrichment
Updated Aug 12, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Aug 12, 2026
Updated Aug 12, 2026
Exploited since n/a
EUVD-2026-57083