{"id":"CVE-2026-92424","title":"The Content Egg  WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulti…","summary":"The Content Egg  WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulti…","severity":"none","cwe":["CWE-79"],"product":"Content Egg","affected":["content_egg < 11.9.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:09.793","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92424","references":[{"url":"https://wpscan.com/vulnerability/917b8042-b38c-4b6a-9237-1dd08ada157d/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.557Z","slug":"CVE-2026-92424","body":"## Overview\n\nThe Content Egg  WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}