XSS

Ultimate Member – Reflected XSS in Member Directory

The Ultimate Member plugin's Members List page has a sorting feature that accepts user input via GET parameters. The plugin fails to properly escape this input when displaying it back in the HTML, creating a reflected XSS vulnerability.

24 June 2026

Read more

Stored XSS in All-in-One WP Security & Firewall

CVE-2026-8438: All-in-One WP Security & Firewall ≤5.4.7 allows unauthenticated attackers to inject persistent JavaScript via unsanitised input, executing in visitors' browsers across the site.

21 June 2026

Read more