Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads. | |
| Title | Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response | |
| First Time appeared |
Saas.group
Saas.group juicer |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:saas.group:juicer:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Saas.group
Saas.group juicer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T20:39:42.625Z
Reserved: 2026-06-10T17:16:10.427Z
Link: CVE-2026-53737
No data.
Status : Received
Published: 2026-06-10T22:17:01.957
Modified: 2026-06-10T22:17:01.957
Link: CVE-2026-53737
No data.
OpenCVE Enrichment
No data.