๐Ÿ” CVE Alert

CVE-2026-81404

HIGH 7.1

IPGP Visitors Origin < 1.6 - Reflected XSS

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.

Vendor unknown
Product ipgp visitors origin
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ipgp visitors origin

Be the first to know when new high vulnerabilities affecting unknown ipgp visitors origin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / IPGP Visitors Origin
1.3 < 1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8fbfb296-78d8-4f3b-ab21-7a5a4e0ea421/

Credits

Vuln Seeker Cyber Security Team WPScan