Stored Cross-Site Scripting Vulnerability in VI: Include Post By Plugin for WordPress
CVE-2026-5717
6.4MEDIUM
What is CVE-2026-5717?
The VI: Include Post By plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit insufficient input sanitization and output escaping. By misusing the 'class_container' attribute of the 'include-post-by-cat' shortcode, attackers can inject arbitrary web scripts. These scripts execute on pages when users attempt to access them, potentially compromising site security and user trust.
Affected Version(s)
VI: Include Post By 0 <= 0.4.200706