THREAT OPS › Threat News › [NVD] CVE-2026-86790 (MEDIUM 6.8) — The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
[NVD] CVE-2026-86790 (MEDIUM 6.8) — The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2026-86790 CVSS: 6.8 MEDIUM Published: 2026-09-12T06:16:27.427
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Indicators of compromise
- CVE-2026-86790cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86790