โ† All reports

WordPress plugins are vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping on user-supplied attributes.

CybersecurityWordpressApr 22, 2026score 0.173 posts ยท 0 replies across 1 instances
The thread reports multiple vulnerabilities in WordPress plugins, specifically Stored Cross-Site Scripting issues due to insufficient input sanitization and output escaping. These vulnerabilities affect several plugins and versions, posing a security risk to users.

Claims

WordPress plugins are vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping on user-supplied attributes.
Parent: CybersecurityEntity: WordPress pluginsImpact: negativeDate: Apr 22, 2026Target: WordPress plugins are vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping on user-supplied attributes.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24704 ๐Ÿ“Š Score: 6.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Simple Random Posts Shortcode ๐Ÿข Vendor: mkerstner ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the 'simple_random_posts' shortcode in all versions up to, and including, 0.3 due to insu... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24704 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24702 ๐Ÿ“Š Score: 6.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Posts map ๐Ÿข Vendor: lucdecri ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in all versions up to, and including, 0.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This mak... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24702 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24694 ๐Ÿ“Š Score: 6.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: SlideShowPro SC ๐Ÿข Vendor: luetkemj ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24694 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability