CVE-2026-18395
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 06, 2026
Vendor
unknown
Description
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.