MEDIUM
MediaRon LLC
CVE published 2026-10-08
CVE-2026-62127
A Cross Site Scripting (XSS) vulnerability exists in the WP Plugin Info Card plugin for WordPress, affecting versions up to and including 6.3.5. This issue, tracked as CVE-2026-62127, allows for Stored XSS attacks due to improper neutralization of input during web page generation. The vulnerability can be exploited by injecting malicious scripts into the plugin's input fields, potentially leading to unaut [truncated]