{"id":"CVE-2026-87777","title":"The Hostinger Reach  WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will…","summary":"The Hostinger Reach  WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will…","severity":"none","cwe":["CWE-79"],"product":"Hostinger Reach","affected":["hostinger_reach >= 1.0.6 < 1.8.3"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:07.387","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87777","references":[{"url":"https://wpscan.com/vulnerability/4a1f5c2b-a6e5-4e6f-afa3-79726d0eb1e3/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.554Z","slug":"CVE-2026-87777","body":"## Overview\n\nThe Hostinger Reach  WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}