MEDIUM
lcweb-projects
CVE published 2026-04-08
CVE-2026-4025
The PrivateContent Free plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'align' shortcode attribute in the [pc-login-form] shortcode. This issue affects all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. The vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts. Use [truncated]