What is CVE-2026-2487?
CVE-2026-2487 is a Stored Cross-Site Scripting vulnerability in the Admin Custom Login plugin for WordPress through the admin settings in versions up to and including 3.6.4. It affects authenticated users with administrator-level permissions due to insufficient input sanitization and output escaping. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-2487, WordPress üçün Admin Custom Login plaginində administrator parametrləri vasitəsilə 'Stored Cross-Site Scripting' zəifliyidir. Bu, 3.6.4-ə qədər olan versiyalara təsir edir və autentifikasiya olunmuş yüksək səlahiyyətli hücumçulara zərərli skript yerləşdirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Admin Custom Login plugin are affected by CVE-2026-2487?
CVE-2026-2487 affects all versions of the Admin Custom Login plugin up to and including version 3.6.4.
What level of permissions does an attacker need to exploit CVE-2026-2487?
The attacker must be an authenticated high-privileged user with administrator-level permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.