Stored Cross-Site Scripting Vulnerability in Insert Pages Plugin for WordPress
CVE-2026-10089
6.4MEDIUM
What is CVE-2026-10089?
The Insert Pages plugin for WordPress allows attackers with author-level access or higher to exploit a stored cross-site scripting vulnerability. This occurs through insufficient output escaping of post custom field keys when rendering pages that use the shortcode [insert page='ID' display='all']. The vulnerability allows for the injection of malicious web scripts, which could execute for any user visiting the affected pages, potentially compromising user security and site integrity.
Affected Version(s)
Insert Pages 0 <= 3.11.4