Cross-Site Scripting Vulnerability in VK All in One Expansion Unit by Hidekazu Ishikawa
CVE-2026-39483

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39483?

A Cross-Site Scripting (XSS) vulnerability has been identified in the VK All in One Expansion Unit, developed by Hidekazu Ishikawa. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. When exploited, it can lead to stored XSS, enabling unauthorized access to user data and impacts the integrity of the affected WordPress sites. The issue affects versions from n/a up to and including 9.113.3, underscoring the need for timely updates and implementing security measures to mitigate this risk.

Affected Version(s)

VK All in One Expansion Unit 0 <= 9.113.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut | Patchstack Bug Bounty Program
.