Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads. | |
| Title | Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response | |
| First Time appeared |
Saas.group
Saas.group juicer |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:saas.group:juicer:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Saas.group
Saas.group juicer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T20:39:42.625Z
Reserved: 2026-06-10T17:16:10.427Z
Link: CVE-2026-53737
No data.
Status : Received
Published: 2026-06-10T22:17:01.957
Modified: 2026-06-10T22:17:01.957
Link: CVE-2026-53737
No data.
OpenCVE Enrichment
Updated: 2026-06-10T23:15:28Z
Weaknesses