🔐 CVE Alert

CVE-2026-18395

UNKNOWN 0.0

Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Vendor unknown
Product child pages card
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown child pages card

Be the first to know when new unknown vulnerabilities affecting unknown child pages card are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Child Pages Card
0 < 1.09

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/999656c5-2e2d-4af8-9941-36184545f487/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan