Cross-site Scripting Vulnerability in VaultDweller Leyka Plugin
CVE-2025-26766
What is CVE-2025-26766?
The VaultDweller Leyka plugin for WordPress is vulnerable to a stored cross-site scripting (XSS) attack, allowing malicious users to inject harmful scripts into web pages viewed by other users. This vulnerability can be exploited via improper handling of user inputs during web page generation, posing significant risks to site integrity and user data protection. Affected versions include all from the initial release up to version 3.31.8. Website administrators should prioritize patching or updating to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Leyka <= 3.31.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved