MEDIUM
Hidekazu Ishikawa
CVE published 2026-04-08
CVE-2026-39483
A Stored XSS vulnerability was discovered in VK All in One Expansion Unit, a WordPress plugin. The vulnerability is caused by improper neutralization of input during web page generation, allowing an attacker with low privileges to inject malicious scripts into the web page. This could lead to unauthorized actions on behalf of other users. The vulnerability has a CVSS score of 6.5, indicating a medium seve [truncated]