BRIEFING NOTE - CVE-2026-3876 The Prismatic plugin for WordPress versions up to 3.7.3 contains a Stored Cross-Site Scripting (XSS) vulnerability in the 'prismatic_encoded' pseudo-shortcode function. The flaw results from insufficient input sanitization and output escaping of user-supplied attributes within the 'prismatic_decode' function, allowing attackers to inject malicious scripts into website pages. The vulnerability carries a CVSS severity score of 7.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction at the point of injection. An unauthenticated attacker can exploit this by submitting a crafted pseudo-shortcode via comments, causing arbitrary JavaScript to execute when other users access the compromised page. The impact includes confidentiality and integrity compromises across site boundaries due to the cross-site nature of the attack. Currently, there is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, remains inactive on threat tracking hotlists, and has minimal community attention based on EPSS scoring. However, the straightforward attack vector and moderate FAUCET risk score of 37.0 suggest timely patching to versions beyond 3.7.3 remains prudent to prevent future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Specialk | Prismatic | >= 0, <= 3.7.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.