Unrated severityNVD Advisory· Published Aug 6, 2026
Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
CVE-2026-18395
Description
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.09
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/999656c5-2e2d-4af8-9941-36184545f487/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.