Stored Cross-Site Scripting in Private Comment Plugin for WordPress
CVE-2026-2281
4.4MEDIUM
What is CVE-2026-2281?
The Private Comment plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'Label text' setting. This vulnerability allows authenticated attackers with Administrator-level access to inject arbitrary scripts, which can execute on user visits to affected pages. The issue is particularly concerning for multi-site installations and environments where unfiltered_html is disabled, increasing the risk for site administrators and users.
Affected Version(s)
Private Comment 0 <= 0.0.4