Stored Cross-Site Scripting Vulnerability in Sidebar Manager Light Plugin for WordPress
CVE-2026-76562
7.2HIGH
What is CVE-2026-76562?
The Sidebar Manager Light plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting through the 'sbm_description' parameter. This flaw arises from inadequate input sanitization and output escaping, enabling unauthenticated attackers to inject arbitrary scripts. When users access affected pages, the injected scripts are executed, potentially compromising user data and site integrity. This vulnerability affects all versions of Sidebar Manager Light up to and including 1.18.
Affected Version(s)
Sidebar Manager Light 0 <= 1.18