Cross Site Scripting Vulnerability in HollerBox by WordPress
CVE-2026-48885
7.1HIGH
What is CVE-2026-48885?
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in HollerBox versions 2.3.10.1 and below. This vulnerability allows attackers to inject malicious scripts into the web application, potentially compromising user data and leading to further attacks. Sites using affected versions of HollerBox should take immediate steps to update their plugins to safeguard against potential exploitation.
Affected Version(s)
HollerBox <= 2.3.10.1