CVE WATCH / VULNERABILITY DETAIL

CVE-2026-92411

MEDIUMCVSS 6.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-92411 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-92411

MEDIUMCVSS 6.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]