cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forrexcrawler rexcrawler

Direction: ascending
Apr 13, 2026

rexCrawler # CVE-2026-2277

CVE, Research URL

CVE-2026-2277

Application

rexCrawler

Date
Mar 21, 2026
Research Description
The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters in the search-pattern tester page in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.0.15.
Status
vulnerable
May 28, 2026

rexCrawler # CVE-2026-2280

CVE, Research URL

CVE-2026-2280

Application

rexCrawler

Date
May 27, 2026
Research Description
The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.0.15.
Status
vulnerable