Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

Prismatic plugin for WordPress: Stored Cross-Site Scripting via 'prismatic_encoded' shortcode

CVE-2026-3876
Summary

The Prismatic plugin for WordPress has a security flaw that allows attackers to inject malicious code into website pages. This could allow them to take control of your site or steal user data. Update the Prismatic plugin to the latest version, 3.7.4 or later, to fix this issue.

Original title
The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient...
Original description
The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by submitting a comment containing a crafted 'prismatic_encoded' pseudo-shortcode.
nvd CVSS3.1 7.2
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 16 Apr 2026 · Updated: 16 Apr 2026 · First seen: 16 Apr 2026