CVE-2026-92424 PUBLISHED

Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue

Assigner: WPScan
Reserved: 16.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.

Product Status

Vendor Unknown
Product Content Egg
Versions Default: unaffected
  • affected from 0 to 11.9.0 (excl.)

Credits

  • aymen benlamari finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE