What is CVE-2026-57397?
This critical vulnerability allows unauthenticated attackers to perform Cross-Site Scripting (XSS) attacks on sites using the 'Coaching' plugin version 3.9.2 and below. Immediate update to the latest version is required.
Azərbaycanca: Bu kritik boşluq autentifikasiya olunmamış istifadəçilərə 'Coaching' plaqininin 3.9.2 və daha əvvəlki versiyalarına sahib saytlarda cross-site scripting (XSS) hücumu həyata keçirməyə imkan verir. Dərhal plaqini ən son versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-57397?
This vulnerability affects the 'Coaching' plugin version 3.9.2 and below.
Is authentication required to exploit CVE-2026-57397?
No, this vulnerability allows unauthenticated attackers to perform XSS attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.