Stored Cross-Site Scripting in Presto Player Plugin for WordPress
CVE-2026-96682
7.2HIGH
What is CVE-2026-96682?
The Presto Player plugin for WordPress presents a Stored Cross-Site Scripting vulnerability, allowing unauthenticated attackers to inject malicious scripts through comment content in pages. This issue arises from inadequate input sanitization and output escaping in the tag. Initially, an attacker must have their comment approved, but due to WordPress's default settings, all subsequent comments from the same author are automatically approved, enabling potential exploitation of web pages without further intervention from site administrators.
Affected Version(s)
Presto Player 0 <= 4.5.1