Reflected Cross-Site Scripting in Pochipp Plugin for WordPress
CVE-2026-92967

6.1MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-92967?

The Pochipp plugin for WordPress has a vulnerability that allows reflected cross-site scripting through the 'keyword' parameter in versions up to and including 1.20.2. This issue arises from insufficient output escaping where user input is directly interpreted in HTML attributes without the necessary sanitization. Attackers can exploit this flaw by crafting malicious links that, when clicked by users with sufficient permissions, execute arbitrary web scripts in their browsers. This could potentially lead to unauthorized actions on the site.

Affected Version(s)

Pochipp 0 <= 1.20.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.