CVE-2026-10827 Details
Description
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.
A stored CSS injection vulnerability has been identified in the Spectra Legacy WordPress plugin, affecting versions prior to 2.20.0. The issue arises because the plugin fails to properly validate or escape several block style attributes before using them to generate CSS for the front end. This flaw allows users with Contributor roles and above to inject arbitrary CSS into pages that display the affected block. The injected styles are visible to anonymous visitors and can be used to load external resources, alter the page's appearance, or exfiltrate data using CSS attribute selectors. However, it's important to note that JavaScript execution is not possible at this role, as KSES removes script-tag breakouts, limiting the impact to CSS injection.
Users are advised to update the Spectra WordPress plugin to version 2.20.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 1, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/068ac525-423b-42f8-9ef4-f102f948dc78/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Spectra Legacy | < 2.20.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | [email protected] |
Volerion