Reflected Cross-Site Scripting Vulnerability in Rognone Plugin for WordPress
CVE-2026-1451

6.1MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-1451?

The Rognone plugin for WordPress is susceptible to a reflected cross-site scripting vulnerability. This occurs because the plugin fails to properly sanitize the 'a' parameter, allowing attackers to inject arbitrary web scripts into pages. By luring victims into clicking on malicious links, an unauthorized user could exploit this flaw to execute harmful scripts in the context of the victim's browser, leading to potential data theft or further exploitation of the user's session.

Affected Version(s)

rognone 0 <= 0.6.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

san6051
.