EXECUTIVE SUMMARY:
CVE-2026-53608 is a Stored Cross-Site Scripting (XSS) vulnerability with a CVSS score of 8.7, allowing users with editor-level access to inject arbitrary JavaScript that executes for every visitor on every page of the site, potentially leading to session token theft, account takeover through stolen administrator cookies, malware distribution, phishing overlays, or credential harvesting targeting site visitors. The vulnerability occurs because Google Analytics and Google Tag Manager IDs are inserted directly into <script> tag bodies without proper sanitization or validation, allowing an attacker to set these fields to malicious values. Any user with editor-level access can exploit this issue by modifying these fields, resulting in stored XSS execution across the website. The business impact includes unauthorized actions performed in the context of affected users, exposure of sensitive information, and compromise of website visitors through malicious script execution, requiring prompt remediation.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-53608 is a Stored Cross-Site Scripting (XSS) vulnerability with a CVSS score of 8.7, allowing users with editor-level access to inject arbitrary JavaScript that executes for every visitor on every page of the site, potentially leading to session token theft, account takeover through stolen administrator cookies, malware distribution, phishing overlays, or credential harvesting targeting site visitors. The vulnerability occurs because Google Analytics and Google Tag Manager IDs are inserted directly into <script> tag bodies without proper sanitization or validation, allowing an attacker to set these fields to malicious values. Any user with editor-level access can exploit this issue by modifying these fields, resulting in stored XSS execution across the website. The business impact includes unauthorized actions performed in the context of affected users, exposure of sensitive information, and compromise of website visitors through malicious script execution, requiring prompt remediation.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]