---
id: CVE-2026-88788
title: >-
  The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape
  user-supplied styling values before outputting them within a front-end style
  block, and does not verify that a user may edit the target post, allowing
  users with…
summary: >-
  The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape
  user-supplied styling values before outputting them within a front-end style
  block, and does not verify that a user may edit the target post, allowing
  users with…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Text Styler
affected:
  - text_styler <= 1.1.1
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88788'
references:
  - url: 'https://wpscan.com/vulnerability/6175fc16-960b-4dbe-bda2-21b4ce7de54b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00431
epssPercentile: 0.34719
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T10:04:47.485267Z'
ingestedAt: '2026-09-22T06:59:42.678Z'
---

## Overview

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
