Stored Cross-Site Scripting Vulnerability in Quick Table Plugin for WordPress
CVE-2026-6237
6.4MEDIUM
What is CVE-2026-6237?
The Quick Table plugin for WordPress has a vulnerability that allows authenticated attackers with contributor-level access or higher to exploit insufficient input validation and output escaping related to the 'style' attribute of the 'qtbl' shortcode. This can result in the injection of arbitrary web scripts into pages, leading to the execution of these scripts when a user visits the affected pages.
Affected Version(s)
Quick Table 0 <= 1.0.0