Stored Cross-Site Scripting in rexCrawler Plugin for WordPress
CVE-2026-2280
4.8MEDIUM
What is CVE-2026-2280?
The rexCrawler plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping within its admin settings. Authenticated attackers with administrator-level permissions can exploit this issue to inject arbitrary scripts that execute when users access affected pages. This vulnerability specifically impacts multi-site installations and those where unfiltered HTML is disabled, making it crucial for site administrators to implement patches and enhance their security measures.
Affected Version(s)
rexCrawler 0 <= 1.0.15