
CVE-2026-0549 The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0… https://www.cve.org/CVERecord?id=CVE-2026-0549
Post summary
Disclosed stored XSS vulnerability in WordPress Groups plugin up to version 3.10.0, with no PoC, exploitation evidence, or patch information provided.
