THREAT OPS › Threat News › [NVD] CVE-2026-85129 (HIGH 8.8) — The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web
[NVD] CVE-2026-85129 (HIGH 8.8) — The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web
CVE-2026-85129 CVSS: 8.8 HIGH Published: 2026-09-13T21:17:02.063
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the sit
Indicators of compromise
- CVE-2026-85129cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85129