VYPR

VikWidgetsLoader

by WordPress

CVEs (1)

  • CVE-2026-84899Sep 5, 2026
    risk 0.00cvss epss

    The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected…