CVE-2026-10827: CWE-345 Insufficient Verification of Data Authenticity in Spectra Legacy
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.
AI Analysis
Technical Summary
CVE-2026-10827 describes a vulnerability in the Spectra Legacy WordPress plugin prior to version 2.20.0. The plugin fails to validate or escape several block style attributes before incorporating them into CSS output on the front end. Users with Contributor role or above can exploit this to inject arbitrary CSS into affected pages. The CSS injection can lead to forced external resource loading, page defacement or redressing, and data exfiltration via CSS attribute selectors. JavaScript injection is prevented by KSES filtering, so the impact is limited to CSS injection. No official remediation or patch information is provided in the available data.
Potential Impact
The vulnerability allows low-privileged users (Contributor role and above) to inject arbitrary CSS into pages viewed by anonymous visitors. This can result in forced loading of external resources, visual defacement or alteration of page content, and potential data exfiltration through CSS selectors. However, the inability to execute JavaScript limits the severity and scope of potential attacks. The CVSS score of 3.5 reflects a low severity impact with limited confidentiality and integrity impact and no availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role permissions where possible and monitor for suspicious CSS injection attempts. Since JavaScript execution is blocked, the risk is limited to CSS injection effects.
CVE-2026-10827: CWE-345 Insufficient Verification of Data Authenticity in Spectra Legacy
Description
The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.
CVSS v3.1
Score 3.5low
Affected software
Spectra Legacy
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-10827 describes a vulnerability in the Spectra Legacy WordPress plugin prior to version 2.20.0. The plugin fails to validate or escape several block style attributes before incorporating them into CSS output on the front end. Users with Contributor role or above can exploit this to inject arbitrary CSS into affected pages. The CSS injection can lead to forced external resource loading, page defacement or redressing, and data exfiltration via CSS attribute selectors. JavaScript injection is prevented by KSES filtering, so the impact is limited to CSS injection. No official remediation or patch information is provided in the available data.
Potential Impact
The vulnerability allows low-privileged users (Contributor role and above) to inject arbitrary CSS into pages viewed by anonymous visitors. This can result in forced loading of external resources, visual defacement or alteration of page content, and potential data exfiltration through CSS selectors. However, the inability to execute JavaScript limits the severity and scope of potential attacks. The CVSS score of 3.5 reflects a low severity impact with limited confidentiality and integrity impact and no availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role permissions where possible and monitor for suspicious CSS injection attempts. Since JavaScript execution is blocked, the risk is limited to CSS injection effects.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-04T09:35:44.199Z
- State
- PUBLISHED
Threat ID: 6a6d96cfbf32cb7a344cecb9
Added to database: 08/01/2026, 06:48:47 UTC
Last enriched: 08/08/2026, 13:51:12 UTC
Last updated: 09/15/2026, 22:01:31 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.