Prismatic <= 3.7.3 - Unauthenticated Stored Cross-Site Scripting via 'prismatic_encoded' Pseudo-Shortcode
high
The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it p...
- CVSS:
- 7.2
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Apr 15, 2026
CVE-2026-3876 on NVD →
Prismatic <= 2.7 - Reflected Cross-Site Scripting
medium
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
- CVSS:
- 6.1
- Affected:
- up to 2.7
- Fixed in:
- 2.8
- Disclosed:
- Jun 21, 2021
CVE-2021-24409 on NVD →
Prismatic <= 2.7 - Stored Cross-Site Scripting
medium
The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however, hi...
- CVSS:
- 5.4
- Affected:
- up to 2.7
- Fixed in:
- 2.8
- Disclosed:
- Jun 21, 2021
CVE-2021-24408 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database