Stored Cross-Site Scripting in Child Pages Card Plugin by WordPress
CVE-2026-18395

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-18395?

The Child Pages Card plugin for WordPress prior to version 1.09 is susceptible to stored Cross-Site Scripting (XSS) vulnerabilities. The plugin fails to properly sanitize and escape certain shortcode attributes upon outputting them in web pages. This oversight allows users with contributor privileges or higher to inject malicious scripts, compromising the security of the website and potentially leading to unauthorized access or data leakage.

Affected Version(s)

Child Pages Card 0 < 1.09

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo González Pérez
Francisco José Ramírez Vicente
and Iñigo Sánchez Enciso
WPScan
.