THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-85129 (HIGH 8.8) — The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web

[NVD] CVE-2026-85129 (HIGH 8.8) — The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web

mednvdPublished 2026-09-13

CVE-2026-85129 CVSS: 8.8 HIGH Published: 2026-09-13T21:17:02.063

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the sit

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85129