VYPR
High severity7.1NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2026-24955

CVE-2026-24955

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Whizz Plugins whizz-plugins allows Reflected XSS.This issue affects Whizz Plugins: from n/a through <= 1.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected cross-site scripting vulnerability in the Whizz Plugins WordPress plugin allows unauthenticated attackers to inject arbitrary scripts.

The Whizz Plugins WordPress plugin, version 1.9 and earlier, contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This issue exists in the whizz-plugins component and allows attackers to inject arbitrary HTML and JavaScript into affected web pages [1].

Exploitation

An unauthenticated attacker can exploit this vulnerability by crafting a malicious URL containing a script payload. The attack requires user interaction, such as clicking on a crafted link or visiting a specially prepared page [1]. Since there are no authentication requirements, attackers can target any site visitor, including administrators and other high-privilege users [1].

Impact

Successful exploitation enables an attacker to execute arbitrary scripts in the victim's browser within the security context of the affected WordPress site [1]. This can be leveraged to redirect users to malicious sites, display unwanted advertisements, steal session cookies, or inject other HTML content [1]. The vulnerability is considered moderately dangerous and is expected to be targeted in mass-exploit campaigns due to its low complexity and no authentication requirement [1].

Mitigation

The vulnerability has been addressed in version 2.0.0 of the Whizz Plugins plugin [1]. Users are strongly advised to update immediately. For those unable to update, Patchstack provides a mitigation rule to block attacks until a patched version is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.