CVE-2026-56006HIGH NVDCVSS Score 7.1Severity HIGHPublished Jun 25, 2026Vendor unknownDescriptionUnauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/h5p/vulnerability/wordpress-h5p-plugin-1-17-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve