Reflected Cross-Site Scripting Vulnerability in Rognone Plugin for WordPress
CVE-2026-1451
6.1MEDIUM
What is CVE-2026-1451?
The Rognone plugin for WordPress is susceptible to a reflected cross-site scripting vulnerability. This occurs because the plugin fails to properly sanitize the 'a' parameter, allowing attackers to inject arbitrary web scripts into pages. By luring victims into clicking on malicious links, an unauthorized user could exploit this flaw to execute harmful scripts in the context of the victim's browser, leading to potential data theft or further exploitation of the user's session.
Affected Version(s)
rognone 0 <= 0.6.2