Stored Cross-Site Scripting Vulnerability in Show Posts Plugin for WordPress
CVE-2026-4022
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 March 2026
What is CVE-2026-4022?
The Show Posts plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping of the 'post_type' shortcode attribute in the 'swiftpost-list' shortcode. This vulnerability can be exploited by authenticated users with contributor-level access or higher, allowing them to inject malicious scripts. Once compromised, any user accessing the affected pages may unknowingly execute the injected scripts, leading to potential data theft or further site compromise.
Affected Version(s)
Show Posts list β Easy designs, filters and more 0 <= 1.1.0