๐Ÿ” CVE Alert

CVE-2026-39483

MEDIUM 6.5

WordPress VK All in One Expansion Unit plugin <= 9.113.3 - Cross Site Scripting (XSS) vulnerability

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
8th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3.

CWE CWE-79
Vendor hidekazu ishikawa
Product vk all in one expansion unit
Published Apr 8, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for hidekazu ishikawa vk all in one expansion unit

Be the first to know when new medium vulnerabilities affecting hidekazu ishikawa vk all in one expansion unit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Hidekazu Ishikawa / VK All in One Expansion Unit
0 โ‰ค 9.113.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/vk-all-in-one-expansion-unit/vulnerability/wordpress-vk-all-in-one-expansion-unit-plugin-9-113-3-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

timomangcut | Patchstack Bug Bounty Program