CVE-2026-92991 Details
Description
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
A cross-site scripting (XSS) vulnerability has been identified in the Biggop Library, present in various WordPress plugins, including 'bdthemes-element-pack-lite' version 8.7.14, 'bdthemes-prime-slider-lite' version 4.4.5, 'live-copy-paste' version 1.5.4, 'pixel-gallery' version 2.1.14, 'smart-admin-assistant' version 2.2.0, and 'ultimate-post-kit' version 4.2.0. The vulnerability arises from insufficient output escaping in the 'display_id' parameter, allowing attackers who compromise the Sigmative API server to inject arbitrary scripts. These scripts execute when a user accesses the affected page.
Users can update to the latest version of the affected plugins to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Biggop Library | >= 4.4.5, < 4.4.6 (semver) |
CPE
Remediation
| |
| BDThemes Element Pack Lite | All versions |
CPE
Remediation
| |
| BDThemes Prime Slider Lite | All versions |
CPE
Remediation
| |
| Live Copy Paste | All versions |
CPE
Remediation
| |
| Pixel Gallery | All versions |
CPE
Remediation
| |
| Smart Admin Assistant | All versions |
CPE
Remediation
| |
| Ultimate Post Kit | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion