OVERVIEW CVE-2026-4074 is a Stored Cross-Site Scripting (XSS) vulnerability in the Quran Live Multilanguage WordPress plugin affecting all versions through 1.0.3. The vulnerability exists in the plugin's shortcode handling mechanism, where the quran_live_render() function fails to sanitize user-supplied shortcode attributes ('cheikh' and 'lang') before passing them directly into inline JavaScript code blocks. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.4 (MEDIUM) with a network-based attack vector, low attack complexity, and low privilege requirements (Contributor-level access). The issue allows authenticated attackers to inject arbitrary JavaScript code that executes in the browser context of any user viewing an affected page, resulting in confidentiality and integrity impacts. The flaw stems from improper input sanitization and output escaping, compounded by the use of PHP short tags that echo unsanitized values directly into script contexts. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, and the EPSS score of 0.000160 indicates minimal real-world exploitation activity. The FAUCET Risk Score of 35.0/100 suggests moderate concern. No publicly available exploit code has been widely distributed, and community attention remains low at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Karim42 | Quran Live Multilanguage | >= 0, <= 1.0.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.