CVE-2026-87777
Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
| Vendor | unknown |
| Product | hostinger reach |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown hostinger reach
Be the first to know when new unknown vulnerabilities affecting unknown hostinger reach are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Hostinger Reach
1.0.6 < 1.8.3
References
Credits
Dmitrii Ignatyev WPScan