WordPress plugins are vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping on user-supplied attributes.
Claims
WordPress plugins are vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping on user-supplied attributes.
Parent: CybersecurityEntity: WordPress pluginsImpact: negativeDate: Apr 22, 2026Target: WordPress plugins are vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping on user-supplied attributes.
Source posts
๐จ EUVD-2026-24704
๐ Score: 6.4/10 (CVSS v3.1)
๐ฆ Product: Simple Random Posts Shortcode
๐ข Vendor: mkerstner
๐
Updated: 2026-04-22
๐ The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the 'simple_random_posts' shortcode in all versions up to, and including, 0.3 due to insu...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24704
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24702
๐ Score: 6.4/10 (CVSS v3.1)
๐ฆ Product: Posts map
๐ข Vendor: lucdecri
๐
Updated: 2026-04-22
๐ The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in all versions up to, and including, 0.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This mak...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24702
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24694
๐ Score: 6.4/10 (CVSS v3.1)
๐ฆ Product: SlideShowPro SC
๐ข Vendor: luetkemj
๐
Updated: 2026-04-22
๐ The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24694
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability