Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads. | |
| Title | Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response | |
| First Time appeared |
Saas.group
Saas.group juicer |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:saas.group:juicer:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Saas.group
Saas.group juicer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-10T20:39:42.625Z
Updated: 2026-06-11T14:05:55.151Z
Reserved: 2026-06-10T17:16:10.427Z
Link: CVE-2026-53737
Updated: 2026-06-11T14:05:49.796Z
Status : Deferred
Published: 2026-06-10T22:17:01.957
Modified: 2026-06-11T15:22:26.633
Link: CVE-2026-53737
No data.
ReportizFlow