What is CVE-2026-57384?
This vulnerability is a Subscriber Cross Site Scripting (XSS) flaw found in WishList Member X plugin versions 3.32.0 and below. Due to insufficient sanitization of user-supplied input, an authenticated user with the 'Subscriber' role can inject malicious scripts. Immediate update to the latest version is strongly advised.
Azərbaycanca: Bu zəiflik WishList Member X plaginində 3.32.0 və daha əvvəlki versiyalarda aşkar edilmiş 'Subscriber Cross Site Scripting (XSS)' problemidir. Müştəri tərəfindən göndərilən məlumatların zəif təmizlənməsi səbəbindən autentifikasiya olunmuş 'Subscriber' roluna malik istifadəçi zərərli skript yeridə bilər. Plaqini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin and versions are affected by CVE-2026-57384?
This vulnerability was found in WishList Member X plugin versions 3.32.0 and below.
What privileges must an attacker have to exploit CVE-2026-57384?
The attacker must be an authenticated user with the 'Subscriber' role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.