Medium severity6.1NVD Advisory· Published Dec 3, 2017· Updated May 13, 2026
CVE-2017-17096
CVE-2017-17096
Description
Cross-site scripting (XSS) vulnerability in the Content Cards plugin before 0.9.7 for WordPress allows remote attackers to inject arbitrary JavaScript via crafted OpenGraph data.
Affected products
1- cpe:2.3:a:content_cards_project:content_cards:*:*:*:*:*:wordpress:*:*Range: <0.9.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- wordpress.org/plugins/content-cards/nvdRelease NotesVendor Advisory
- wpvulndb.com/vulnerabilities/8971nvdThird Party Advisory
News mentions
0No linked articles in our index yet.