What is CVE-2026-8790?
CVE-2026-8790 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Football Pool plugin for WordPress, affecting the Shoutbox widget via the `shouttext` POST parameter. It impacts all versions up to and including 2.13.4 due to insufficient input sanitization and output escaping. Users should update to the latest version or temporarily disable the Shoutbox feature.
Azərbaycanca: CVE-2026-8790, WordPress üçün Football Pool plagininin Shoutbox vidjetində `shouttext` POST parametri vasitəsilə Reflected Cross-Site Scripting (XSS) zəifliyidir. Bu, 2.13.4 daxil olmaqla bütün versiyalara təsir edir və zəif giriş təmizlənməsi səbəbindən baş verir. İstifadəçilər plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq Shoutbox funksiyasını söndürməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which component of the Football Pool plugin for WordPress is affected by CVE-2026-8790?
CVE-2026-8790 affects the Shoutbox widget of the plugin.
What temporary measure is recommended to users to mitigate CVE-2026-8790?
Users should temporarily disable the Shoutbox feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.