VYPR

Wavesurfer

by WordPress

CVEs (1)

  • CVE-2026-1909MedFeb 6, 2026
    risk 0.42cvss 6.4epss 0.00

    The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping on the 'src' attribute. This makes it possible for…