PT-2026-2827 · WordPress · Wordpress List Site Contributors

·

CVE-2026-0594

·

Publicado

2026-01-14

·

Atualizado

2026-02-07

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress List Site Contributors plugin versions up to and including 1.1.8
Description The List Site Contributors plugin for WordPress is susceptible to Reflected Cross-Site Scripting. This is due to inadequate input sanitization and output escaping of the alpha parameter. An unauthenticated attacker can inject arbitrary web scripts into pages, which will execute if a user is tricked into clicking a malicious link. The API endpoint potentially affected involves the alpha parameter.
Recommendations Update the WordPress List Site Contributors plugin to a version newer than 1.1.8.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0594

Produtos afetados

Wordpress List Site Contributors