Cross-Site Scripting Vulnerability in Zahlan Categories Images Plugin for WordPress
CVE-2026-40734

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2026-40734?

The Zahlan Categories Images plugin for WordPress suffers from a vulnerability that enables DOM-Based Cross-Site Scripting (XSS). This flaw arises due to improper handling of user input during web page generation. Attackers can exploit this weakness to inject malicious scripts into web pages, potentially compromising the security of users visiting the affected website. This issue impacts versions from n/a up to and including 3.3.1, stressing the importance of updating to secure versions and implementing proper input sanitization.

Affected Version(s)

Categories Images 0 <= 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut | Patchstack Bug Bounty Program
.