What is CVE-2026-48094?
The ShareOpenly WordPress plugin before version 1.2.1 contains a Cross-Site Scripting (XSS) vulnerability due to missing `esc_url()` escaping on a URL variable before HTML rendering. This could allow an attacker to inject and execute malicious scripts in a victim's browser. Users should update the plugin to the latest version.
Azərbaycanca: ShareOpenly WordPress plugin-in 1.2.1 öncəsi versiyalarında URL daxiletməsində `esc_url()` funksiyasının istifadə edilməməsi səbəbindən Cross-Site Scripting (XSS) zəifliyi aşkar edilib. Bu zəiflik təcavüzkara qurbanın brauzerində zərərli skript icra etməyə imkan yarada bilər. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: WordPress
FAQ2
Which versions of the ShareOpenly WordPress plugin are affected by the CVE-2026-48094 XSS vulnerability?
All versions of the ShareOpenly plugin before 1.2.1 are affected.
What is the root cause of CVE-2026-48094?
The root cause is the missing `esc_url()` escaping on a URL variable before HTML rendering, which allows for malicious script injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.