๐Ÿ” CVE Alert

CVE-2026-39517

MEDIUM 6.5

WordPress Blog Filter plugin <= 1.7.6 - Cross Site Scripting (XSS) vulnerability

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
8th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6.

CWE CWE-79
Vendor a wp life
Product blog filter
Published Apr 8, 2026
Last Updated Apr 10, 2026
Stay Ahead of the Next One

Get instant alerts for a wp life blog filter

Be the first to know when new medium vulnerabilities affecting a wp life blog filter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

A WP Life / Blog Filter
0 โ‰ค 1.7.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/blog-filter/vulnerability/wordpress-blog-filter-plugin-1-7-6-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

Jitlada | Patchstack Bug Bounty Program