{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-03T06:14:36.508","vulnerabilities":[{"cve":{"id":"CVE-2026-2502","sourceIdentifier":"security@wordfence.com","published":"2026-02-19T07:17:46.570","lastModified":"2026-06-17T10:31:12.120","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the debug log page."},{"lang":"es","value":"El plugin xmlrpc attacks blocker para WordPress es vulnerable a cross-site scripting almacenado en versiones hasta la 1.0, inclusive, a través del encabezado HTTP 'X-Forwarded-For'. Esto se debe a que el plugin confía y registra datos de encabezado IP controlados por el atacante y renderiza entradas del registro de depuración sin escape de salida. Esto hace posible que atacantes no autenticados inyecten scripts web arbitrarios que se ejecutan cuando un administrador ve la página del registro de depuración."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"yehudah","product":"xmlrpc attacks blocker","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-19T17:04:10.688082Z","id":"CVE-2026-2502","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/xmlrpc-attacks-blocker/tags/1.0/plugin.php#L186","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/xmlrpc-attacks-blocker/tags/1.0/plugin.php#L269","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/xmlrpc-attacks-blocker/tags/1.0/plugin.php#L312","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/xmlrpc-attacks-blocker/tags/1.0/plugin.php#L341","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/059f0c64-efcc-4b79-81eb-b4ae9e3e2826?source=cve","source":"security@wordfence.com"}]}}]}