CVE-2026-81754: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in fernandot Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
The Vigilant WordPress plugin up to version 2.10.2 contains a stored cross-site scripting (XSS) vulnerability via the User-Agent header. This flaw allows unauthenticated attackers to inject malicious scripts that execute when users access affected pages. The vulnerability arises from improper input sanitization and output escaping of the User-Agent header during page generation.
AI Analysis
Technical Summary
CVE-2026-81754 is a stored cross-site scripting vulnerability in the Vigilant – 100% Free Security Suite WordPress plugin (versions up to and including 2.10.2). The vulnerability occurs because the plugin does not properly sanitize or escape the User-Agent header input before including it in web pages. An unauthenticated attacker can craft a malicious User-Agent header that is stored and then executed in the context of users visiting pages that trigger a failed login attempt. This can lead to arbitrary script execution in the victim's browser without requiring further interaction from the attacker.
Potential Impact
Successful exploitation allows an unauthenticated attacker to inject and execute arbitrary JavaScript in the context of users visiting the vulnerable site, potentially leading to session hijacking, defacement, or other client-side impacts. The vulnerability does not affect availability but compromises confidentiality and integrity of user interactions.
Mitigation Recommendations
A fix is available in versions later than 2.10.2. Users should upgrade the Vigilant plugin to a version higher than 2.10.2 once released. Until then, consider restricting or sanitizing User-Agent headers at the web server or application firewall level as a temporary mitigation. Monitor the vendor advisory for official patch releases.
CVE-2026-81754: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in fernandot Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
Description
The Vigilant WordPress plugin up to version 2.10.2 contains a stored cross-site scripting (XSS) vulnerability via the User-Agent header. This flaw allows unauthenticated attackers to inject malicious scripts that execute when users access affected pages. The vulnerability arises from improper input sanitization and output escaping of the User-Agent header during page generation.
CVSS v3.1
Score 7.2high
Affected software
fernandot
Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-81754 is a stored cross-site scripting vulnerability in the Vigilant – 100% Free Security Suite WordPress plugin (versions up to and including 2.10.2). The vulnerability occurs because the plugin does not properly sanitize or escape the User-Agent header input before including it in web pages. An unauthenticated attacker can craft a malicious User-Agent header that is stored and then executed in the context of users visiting pages that trigger a failed login attempt. This can lead to arbitrary script execution in the victim's browser without requiring further interaction from the attacker.
Potential Impact
Successful exploitation allows an unauthenticated attacker to inject and execute arbitrary JavaScript in the context of users visiting the vulnerable site, potentially leading to session hijacking, defacement, or other client-side impacts. The vulnerability does not affect availability but compromises confidentiality and integrity of user interactions.
Mitigation Recommendations
A fix is available in versions later than 2.10.2. Users should upgrade the Vigilant plugin to a version higher than 2.10.2 once released. Until then, consider restricting or sanitizing User-Agent headers at the web server or application firewall level as a temporary mitigation. Monitor the vendor advisory for official patch releases.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-08-27T12:18:35.158Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa379d891cc7f38489ada42
Added to database: 09/11/2026, 03:47:36 UTC
Last enriched: 09/11/2026, 04:01:58 UTC
Last updated: 09/11/2026, 04:11:31 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.