What is CVE-2026-10827?
CVE-2026-10827 is a CSS injection vulnerability in the Spectra Legacy WordPress plugin versions before 2.20.0. It allows users with Contributor role and above to inject arbitrary CSS into pages rendering affected blocks via unvalidated block style attributes. Immediate update to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-10827, WordPress üçün Spectra Legacy plugin-inin 2.20.0-dan əvvəlki versiyalarında CSS injection zəifliyidir. Bu, Contributor və yuxarı roluna malik istifadəçilərə müəyyən blok stil atributları vasitəsilə ön hissədə ixtiyari CSS kodu yeritməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which user roles can be affected by the CVE-2026-10827 vulnerability?
This vulnerability affects users with the Contributor role and above.
What is the primary recommendation for CVE-2026-10827?
Immediate update to the latest plugin version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.