Reflected Cross-Site Scripting Vulnerability in Blog Settings Plugin for WordPress
CVE-2026-6704
6.1MEDIUM
What is CVE-2026-6704?
The Blog Settings plugin for WordPress is susceptible to a reflected cross-site scripting vulnerability through the 'page' parameter in versions up to and including 1.0. This flaw is primarily caused by inadequate input sanitization and output escaping. Malicious actors can potentially exploit this vulnerability to inject arbitrary web scripts into pages, executing them if a user is manipulated into clicking a specially crafted link. As a result, users of the impacted plugin should ensure they follow best practices for security to mitigate possible exploitation.
Affected Version(s)
Blog Settings 0 <= 1.0