Back to overview

CVE-2026-10531

Description
The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

Metadata

CVE ID
CVE-2026-10531
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-01 11:15 UTC
Published
2026-06-24 06:00 UTC
Last updated
2026-06-24 06:00 UTC
Vendor / Product
Unknown / AI Share & Summarize
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown AI Share & Summarize 0 < 2.0.4
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
Back to overview