VYPR

Product Icon Badge

by WordPress

CVEs (1)

  • CVE-2026-8707MedMay 27, 2026
    risk 0.40cvss 6.1epss

    The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…