VYPR

ShareOpenly

by WordPress

CVEs (1)

  • CVE-2026-48094MedAug 7, 2026
    risk 0.27cvss epss

    The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. This variable is constructed from `home_url(…