What is CVE-2026-5391?
CVE-2026-5391 is a Stored Cross-Site Scripting vulnerability in the LatePoint plugin for WordPress, exploitable via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode. It affects all versions up to and including 5.3.2 due to insufficient input sanitization and output escaping. Updating the plugin to the latest available version is recommended.
Azərbaycanca: CVE-2026-5391, WordPress üçün LatePoint plaginində 'latepoint_resources' shortcode-unun 'btn_wrapper_classes' atributu vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyidir. Bu zəiflik 5.3.2-ə qədər olan versiyalara təsir göstərir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin does CVE-2026-5391 affect and what is the version range?
CVE-2026-5391 affects the LatePoint plugin for WordPress, all versions up to and including 5.3.2.
Through which attribute can the CVE-2026-5391 vulnerability be exploited for Stored XSS?
This vulnerability can be exploited via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.