Stored Cross-Site Scripting Vulnerability in Contextual Related Posts Plugin for WordPress
CVE-2026-2986
6.4MEDIUM
What is CVE-2026-2986?
The Contextual Related Posts plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate input sanitization and output escaping in the 'other_attributes' parameter. This issue affects versions 4.2.1 and earlier, allowing authenticated attackers with contributor-level access or higher to insert malicious web scripts into pages. These scripts can execute whenever a user accesses the affected page, leading to potential data theft or session hijacking.
Affected Version(s)
Contextual Related Posts 0 <= 4.2.1