Cross Site Scripting Vulnerability in ManageWP Worker Plugin
CVE-2026-39463
7.1HIGH
What is CVE-2026-39463?
The ManageWP Worker Plugin, up to version 4.9.31, is susceptible to an unauthenticated Cross Site Scripting (XSS) vulnerability. This issue allows attackers to inject malicious scripts into the application, which can be executed in the context of the user’s session, potentially leading to data theft or unauthorized actions. It is essential for users of this plugin to update to a patched version promptly to mitigate exposure to such security risks.
Affected Version(s)
ManageWP Worker <= 4.9.31