Cross-Site Scripting Vulnerability in MediaRon WP Plugin Info Card
CVE-2026-62127

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 October 2026

What is CVE-2026-62127?

A vulnerability has been identified in the WP Plugin Info Card developed by MediaRon LLC, allowing attackers to exploit stored cross-site scripting (XSS). This occurs due to improper neutralization of user input during web page generation, potentially enabling malicious scripts to be executed in the context of users interacting with the affected plugin. Versions from n/a up to 6.3.5 are impacted, highlighting a serious concern for website administrators seeking to ensure secure operations.

Affected Version(s)

WP Plugin Info Card 0 <= 6.3.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

V1T | Patchstack Bug Bounty Program
.