๐Ÿ” CVE Alert

CVE-2026-9577

UNKNOWN 0.0

Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.

Vendor unknown
Product post status notifier lite
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown post status notifier lite

Be the first to know when new unknown vulnerabilities affecting unknown post status notifier lite are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Post Status Notifier Lite
0 < 1.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b316e14a-4260-43c4-996c-345c7f9f7d74/

Credits

Luca Jungnickel WPScan