MEDIUM
wordplus
CVE published 2026-09-16
CVE-2026-18555
The Better Messages plugin for WordPress has a reflected XSS vulnerability via the 'icn' parameter in versions up to 2.15.22. This allows unauthenticated attackers to inject web scripts if they can trick a user into clicking a link. The vulnerability has a CVSS score of 6.1 and a severity of MEDIUM. Defenders should prioritize verifying exposure of Better Messages plugin versions up to 2.15.22 and assess [truncated]