Stored Cross-Site Scripting Vulnerability in WP-Clippy Plugin for WordPress
CVE-2026-5505
6.4MEDIUM
What is CVE-2026-5505?
The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input validation and output escaping on attributes supplied by users. This vulnerability allows authenticated attackers with contributor-level access or higher to inject malicious scripts into pages. When a user accesses a compromised page, the injected scripts execute, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
WP-Clippy 0 <= 1.0.0