CVE-2026-17010 PUBLISHED

Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta

Assigner: WPScan
Reserved: 24.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.

Product Status

Vendor Unknown
Product Saitama Addon Pack
Versions Default: unknown
  • affected from 0 to 1.0.8 (incl.)

Credits

  • testoun finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE