Stored Cross-Site Scripting in Child Pages Card Plugin by WordPress
CVE-2026-18395
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-18395?
The Child Pages Card plugin for WordPress prior to version 1.09 is susceptible to stored Cross-Site Scripting (XSS) vulnerabilities. The plugin fails to properly sanitize and escape certain shortcode attributes upon outputting them in web pages. This oversight allows users with contributor privileges or higher to inject malicious scripts, compromising the security of the website and potentially leading to unauthorized access or data leakage.
Affected Version(s)
Child Pages Card 0 < 1.09
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.