MEDIUM
Spiffy Plugin
CVE published 2026-08-28
CVE-2026-39071
The Spiffy Plugin for WordPress before version 5.0.9 is vulnerable to Stored Cross-Site Scripting via the Event Title field. This vulnerability allows an authenticated attacker with the lowest privileged role (contributor) to potentially inject scripts, redirect users, or control accounts. The CVE record was published on 2026-08-28T20:17:28.670Z. WordPress administrators and users of the Spiffy Plugin, es [truncated]