What is CVE-2026-16942?
CVE-2026-16942 is a Stored XSS vulnerability in the WP Custom HTML Page plugin (up to version 0.6.2) that fails to sanitize HTML stored via a custom page handler. It allows users with the Author role to inject JavaScript, which is then served unescaped at a public URL and executed for visitors. The plugin should be updated or temporarily disabled.
Azərbaycanca: CVE-2026-16942, WP Custom HTML Page pluginində (0.6.2 versiyasına qədər) aşkar edilmiş Stored XSS zəifliyidir. Bu, 'Author' roluna malik istifadəçilərə filterlənməmiş HTML/JavaScript saxlamağa imkan verir və kod ictimai URL-də icra olunaraq ziyarətçilərə təsir göstərir. Plugin dərhal yenilənməli və ya müvəqqəti olaraq deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which user roles are affected by CVE-2026-16942 in the WP Custom HTML Page plugin?
The vulnerability allows users with the Author role to store unfiltered HTML/JavaScript.
How can the WP Custom HTML Page plugin be secured against CVE-2026-16942?
The plugin should be updated or temporarily disabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.