Description
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all versions up to, and including, 4.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability occurs because the plugin uses a custom wp_kses implementation with permissive allowed HTML tags, and then performs a str_replace operation that injects HTML after sanitization, allowing event handlers to be introduced through the %total placeholder in the style attribute.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version
Timeline
| 2026-04-17: | Vendor Notified |
| 2026-05-27: | Disclosed |
Credits
Muhammad Yudha - DJ
References
www.wordfence.com/...-3d4d-4f70-a749-6d6c552c7553?source=cve
plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
plugins.trac.wordpress.org/...0shariff&sfp_email=&sfph_mail=