What is CVE-2026-9577?
CVE-2026-9577 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Post Status Notifier Lite WordPress plugin before version 1.13.0, caused by improper escaping of the `mod` URL parameter reflected on the admin settings page. It affects authenticated administrators. Update the plugin to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-9577, Post Status Notifier Lite WordPress plaginində 1.13.0 versiyasından əvvəl administrator panelində `mod` URL parametrinin düzgün escap edilməməsi səbəbilə Reflected Cross-Site Scripting (XSS) zəifliyidir. Bu, autentifikasiya olunmuş administrator kontekstində işləyir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What risk does CVE-2026-9577 pose for the Post Status Notifier Lite plugin?
CVE-2026-9577 allows a Reflected Cross-Site Scripting (XSS) attack due to improper escaping of the `mod` URL parameter in the plugin. This vulnerability specifically operates within the authenticated administrator context on the admin settings page.
How to protect against CVE-2026-9577?
It is recommended to update the Post Status Notifier Lite plugin to version 1.13.0 or later. The vulnerability exists in versions prior to 1.13.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.