← WordPress Vulnerabilities
WordPress security by component

Spectra Legacy

Spectra Legacy is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: spectra-legacy

CVE-2026-10827: Spectra Legacy block styles let Contributors inject arbitrary CSS

Spectra Legacy before 2.20.0 uses several Contributor-controlled block style attributes to construct front-end CSS without adequate validation or escaping. A Contributor-or-higher user can store arbitrary CSS that is served to anonymous visitors of the affected page, enabling defacement, interface redressing, forced external resource loads and limited data exfiltration through attribute selectors. WordPress KSES removes the script-tag breakout at this role, so the published record does not establish JavaScript execution; it also does not disclose the affected block attributes or CSS builder.

PublishedAug 01, 2026
Known safe version2.20.0
Safe version
Aug 01, 2026 CVE-2026-10827
Spectra Legacy block styles let Contributors inject arbitrary CSS
Spectra Legacy before 2.20.0 uses several Contributor-controlled block style attributes to construct front-end CSS without adequate validation or escaping. A Contributor-or-higher user can store arbitrary CSS that is served to anonymous visitors of the affected page, enabling defacement, interface redressing, forced external resource loads and limited data exfiltration through attribute selectors. WordPress KSES removes the script-tag breakout at this role, so the published record does not establish JavaScript execution; it also does not disclose the affected block attributes or CSS builder.
2.20.0
CVEPending
NVDPending