PT-2026-90581 · Undefined · Undefined

CVE-2026-86790

·

Published

2026-09-12

·

Updated

2026-09-17

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Highlight Box versions prior to 1.1
Description Users with the contributor role and above can perform Stored Cross-Site Scripting (XSS) attacks. This occurs because the plugin fails to escape certain shortcode attributes before they are output on a page where the shortcode is embedded.
Recommendations Update to a version newer than 1.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86790

Affected Products

Undefined