CVE-2026-86790
WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
| Vendor | unknown |
| Product | wp highlight box |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp highlight box
Be the first to know when new medium vulnerabilities affecting unknown wp highlight box are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / WP Highlight Box
0 ≤ 1.0
References
Credits
Pablo González and Francisco José Ramírez WPScan