Unauthenticated Cross Site Scripting Vulnerability in H5P Plugin by WordPress
CVE-2026-56006
7.1HIGH
What is CVE-2026-56006?
The H5P Plugin for WordPress is impacted by an unauthenticated Cross Site Scripting (XSS) vulnerability that affects versions up to 1.17.6. This issue may allow attackers to exploit the vulnerability without authentication, potentially leading to malicious scripts being executed in the context of a victim's browser session. It is crucial for users to address this vulnerability in order to safeguard their WordPress installations and user data.
Affected Version(s)
H5P <= 1.17.6