MEDIUM
PublishPress
CVE published 2026-04-08
CVE-2026-39482
A DOM-Based XSS vulnerability was discovered in the Post Expirator plugin for WordPress. This issue, tracked as CVE-2026-39482, allows attackers to inject malicious scripts into web pages. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The Post Expirator plugin is used by WordPress administrators to schedule posts to expire. The vulnerability occurs when user input is not [truncated]