Stored Cross-Site Scripting Vulnerability in Credits Shortcode Plugin for WordPress
CVE-2026-6256
6.4MEDIUM
What is CVE-2026-6256?
The Credits Shortcode plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability through the 'link' attribute of the 'credits' shortcode. This vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes. As a result, authenticated attackers with contributor-level access and higher can inject malicious web scripts into pages, which will execute when users access those compromised pages. It is crucial for users and administrators to ensure their plugins are updated to prevent exploitation.
Affected Version(s)
Credits Shortcode 0 <= 1.2