Reflected Cross-Site Scripting in Pochipp Plugin for WordPress
CVE-2026-92967
6.1MEDIUM
What is CVE-2026-92967?
The Pochipp plugin for WordPress has a vulnerability that allows reflected cross-site scripting through the 'keyword' parameter in versions up to and including 1.20.2. This issue arises from insufficient output escaping where user input is directly interpreted in HTML attributes without the necessary sanitization. Attackers can exploit this flaw by crafting malicious links that, when clicked by users with sufficient permissions, execute arbitrary web scripts in their browsers. This could potentially lead to unauthorized actions on the site.
Affected Version(s)
Pochipp 0 <= 1.20.2