Cross-Site Scripting Vulnerability in Name Directory by Jeroen Peters
CVE-2026-104396

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104396?

A stored cross-site scripting (XSS) vulnerability exists in the Name Directory plugin developed by Jeroen Peters. This flaw allows attackers to inject malicious scripts into web pages, potentially compromising user data and performing unauthorized actions under the guise of authentic users. The vulnerability affects all versions from n/a up to 1.34.2, highlighting the importance of timely updates and implementing security measures to mitigate the risks associated with such vulnerabilities.

Affected Version(s)

Name Directory 0 <= 1.34.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Masaya Morita (@mrtmyix) | Patchstack Bug Bounty Program
.