What is CVE-2026-18395?
The Child Pages Card WordPress plugin before version 1.09 does not sanitize and escape some of its shortcode attributes before outputting them, allowing users with Contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks. Users should immediately update the plugin to the latest version.
Azərbaycanca: WordPress "Child Pages Card" plagininin 1.09-dan əvvəlki versiyalarında qısa kod atributlarının sanitizasiya edilməməsi səbəbindən Contributor rolundan yuxarı istifadəçilər Stored Cross-Site Scripting (XSS) hücumu həyata keçirə bilər. Plagindən istifadə edən administratorlar dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress user roles are affected by the CVE-2026-18395 vulnerability in the "Child Pages Card" plugin?
The vulnerability allows users with the Contributor role and above to perform Stored XSS attacks.
What is the recommended action to mitigate the CVE-2026-18395 vulnerability?
To mitigate this vulnerability, users should immediately update the plugin to version 1.09 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.