MEDIUM
alphawolf
CVE published 2026-08-05
CVE-2026-7441
The Simple Yearly Archive plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes. Authenticated attackers with Contributor-level access and above can inject arbitrary web scripts in page [truncated]