VYPR

VI: Include Post By

by WordPress

CVEs (1)

  • CVE-2026-5717MedApr 15, 2026
    risk 0.42cvss 6.4epss 0.00

    The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in all versions up to, and including, 0.4.200706 due to insufficient input sanitization and output escaping on…