VYPR

KeyWord Collector

by WordPress

CVEs (1)

  • CVE-2026-88905Oct 11, 2026
    risk 0.00cvss —epss —

    The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the…