PT-2026-51666 · WordPress · Ai Share & Summarize

·

CVE-2026-10531

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AI Share & Summarize versions prior to 2.0.4
Description Users with the Contributor role and above can perform Stored Cross-Site Scripting (XSS) attacks. This occurs because the plugin fails to sanitize and escape certain shortcode attributes, specifically the title style attribute, before they are output on a page. Stored XSS is a type of vulnerability where a malicious script is permanently stored on the target server and executed in the browser of users who visit the affected page.
Recommendations Update AI Share & Summarize to version 2.0.4 or later. As a temporary mitigation, restrict the use of the title style shortcode attribute for users with the Contributor role.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10531

Affected Products

Ai Share & Summarize