๐Ÿ” CVE Alert

CVE-2026-88905

UNKNOWN 0.0

KeyWord Collector <= 1.4 - Unauthenticated Stored XSS and Settings Update via WPKeyWordSettings

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output.

Vendor unknown
Product keyword collector
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown keyword collector

Be the first to know when new unknown vulnerabilities affecting unknown keyword collector are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / KeyWord Collector
0 โ‰ค 1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/93503140-af69-4734-bf65-bc781b761c47/

Credits

Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan