HIGH
2winfactor
CVE published 2026-10-10
CVE-2026-96682
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content. This vulnerability allows unauthenticated attackers to inject web scripts into pages, which execute when a user accesses an injected page. Initial comment approval is required, but subsequent comments from the same author are auto-approved by default.