Reflected Cross-Site Scripting Vulnerability in NS Product Icon Badge Plugin for WordPress
CVE-2026-8707

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2026-8707?

The NS Product Icon Badge plugin for WordPress is susceptible to a reflected cross-site scripting (XSS) vulnerability. This issue arises from inadequate input sanitization and output escaping in the handling of the PHP_SELF variable. Unauthenticated attackers can craft malicious scripts, and if a user is tricked into clicking a specially crafted link, these scripts could execute in the context of their session, compromising their security. All versions up to and including 1.2.4 are affected, making it crucial for site administrators to ensure their installations are updated and secure.

Affected Version(s)

NS Product icon badge 0 <= 1.2.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdulsamad Yusuf
.