๐Ÿ” CVE Alert

CVE-2026-87777

UNKNOWN 0.0

Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.

Vendor unknown
Product hostinger reach
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown hostinger reach

Be the first to know when new unknown vulnerabilities affecting unknown hostinger reach are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Hostinger Reach
1.0.6 < 1.8.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4a1f5c2b-a6e5-4e6f-afa3-79726d0eb1e3/

Credits

Dmitrii Ignatyev WPScan