Stored Cross-Site Scripting Vulnerability in DoFollow Case by Case Plugin for WordPress
CVE-2026-95817
7.2HIGH
What is CVE-2026-95817?
The DoFollow Case by Case plugin for WordPress is exposed to a stored cross-site scripting vulnerability through insufficient input sanitization and output escaping. This issue allows unauthorized attackers to inject malicious scripts into comment content, which, upon approval by an administrator, can execute whenever any user accesses the affected post. Despite comment moderation, the attacker can potentially execute harmful scripts in the browsers of subsequent visitors, posing a significant security risk.
Affected Version(s)
DoFollow Case by Case 0 <= 3.6.0