Review
Post Snippets
CVE published 2026-10-11
CVE-2026-12980
The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed. This vulnerability can lead to XSS attacks, emphasizing the need for defenders to verify the plugin version and ensure it is up-to-date, restric [truncated]