
CVE-2026-0867 The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-archive, ew-category, ew-page, and ew-menu shortc… https://www.cve.org/CVERecord?id=CVE-2026-0867
Post summary
CVE-2026-0867 discloses a stored XSS vulnerability in the Essential Widgets WordPress plugin affecting several shortcodes; no PoC, exploit, patch, or exploitation evidence is provided.
