CVE-2026-1071 describes a Stored Cross-Site Scripting (XSS) vulnerability in the Carta Online WordPress plugin, affecting all versions up to 2.13.0. This flaw, stemming from insufficient input sanitization and output escaping, allows authenticated attackers with administrator privileges to inject malicious web scripts. The vulnerability specifically impacts multi-site WordPress installations or those with unfiltered_html disabled. With a CVSS score of 4.4 (MEDIUM), the attack requires high privileges and has low impact on confidentiality and integrity, with no impact on availability. The attack complexity is high, and user interaction is not required once the script is injected. Currently, there is no evidence of active exploitation, and no public exploit code is available via Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cartaonline | Carta Online | >= 0, <= 2.13.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.