Cross-site Scripting Vulnerability in Emilia Projects Progress Planner
CVE-2026-28116

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 June 2026

What is CVE-2026-28116?

The Progress Planner plugin by Emilia Projects is vulnerable to a Cross-site Scripting (XSS) attack due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. When executed, these scripts can compromise user data, potentially leading to unauthorized access and data breaches. The vulnerability impacts all versions from n/a through 1.9.0, making it critical for users to apply patches or updates to mitigate risk.

Affected Version(s)

Progress Planner <= 1.9.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hongdo | Patchstack Bug Bounty Program
.