CVE 6.5 MEDIUM

WordPress VK All in One Expansion Unit plugin <= 9.113.3 - Cross Site Scripting (XSS) vulnerability_CVE-2026-39483

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3.

Basic Information

ID CVE-2026-39483
Source Patchstack
Published Apr 8, 2026 at 08:30
Modified Apr 13, 2026 at 16:17

Affected Product

Vendor Hidekazu Ishikawa
Product VK All in One Expansion Unit
Affected Versions Hidekazu Ishikawa VK All in One Expansion Unit 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.