Stored Cross-Site Scripting Vulnerability in CM CSS Columns Plugin for WordPress
CVE-2026-1098
6.4MEDIUM
What is CVE-2026-1098?
The CM CSS Columns plugin for WordPress is susceptible to Stored Cross-Site Scripting due to insufficient sanitization and escaping of user input on the 'tag' shortcode attribute. This vulnerability can be exploited by authenticated users with Contributor-level access and higher, allowing them to inject arbitrary scripts into pages. These scripts will execute whenever a user accesses a page containing the injected content, posing a risk to site security and user data.
Affected Version(s)
CM CSS Columns 0 <= 1.2.1