CVE-2026-9577
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
| Vendor | unknown |
| Product | post status notifier lite |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown post status notifier lite
Be the first to know when new unknown vulnerabilities affecting unknown post status notifier lite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Post Status Notifier Lite
0 < 1.13.0
References
Credits
Luca Jungnickel WPScan