Skip to main content
EPSS 0.1%top 99%

CVE-2026-10827: CWE-345 Insufficient Verification of Data Authenticity in Spectra Legacy

0
Low
Published: 08/01/2026 (08/01/2026, 06:00:11 UTC)
Source: CVE Database V5
Product: Spectra Legacy

Description

The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are served to anonymous visitors of those pages and can force external resource loads, deface/redress the page, or exfiltrate data via CSS attribute selectors. JavaScript execution is not possible at this role (the script-tag breakout is removed by KSES), so the impact is limited to CSS injection.

CVSS v3.1

Score 3.5low

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

Affected software

Spectra Legacy

Affected versions
>=0 <2.20.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 13:51:12 UTC

Technical Analysis

CVE-2026-10827 describes a vulnerability in the Spectra Legacy WordPress plugin prior to version 2.20.0. The plugin fails to validate or escape several block style attributes before incorporating them into CSS output on the front end. Users with Contributor role or above can exploit this to inject arbitrary CSS into affected pages. The CSS injection can lead to forced external resource loading, page defacement or redressing, and data exfiltration via CSS attribute selectors. JavaScript injection is prevented by KSES filtering, so the impact is limited to CSS injection. No official remediation or patch information is provided in the available data.

Potential Impact

The vulnerability allows low-privileged users (Contributor role and above) to inject arbitrary CSS into pages viewed by anonymous visitors. This can result in forced loading of external resources, visual defacement or alteration of page content, and potential data exfiltration through CSS selectors. However, the inability to execute JavaScript limits the severity and scope of potential attacks. The CVSS score of 3.5 reflects a low severity impact with limited confidentiality and integrity impact and no availability impact.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role permissions where possible and monitor for suspicious CSS injection attempts. Since JavaScript execution is blocked, the risk is limited to CSS injection effects.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
WPScan
Date Reserved
2026-06-04T09:35:44.199Z
State
PUBLISHED

Threat ID: 6a6d96cfbf32cb7a344cecb9

Added to database: 08/01/2026, 06:48:47 UTC

Last enriched: 08/08/2026, 13:51:12 UTC

Last updated: 09/15/2026, 22:01:31 UTC

Views: 61

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses