CVE-2026-10092Patch

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and including, 1.163 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because the plugin processes the [cincopa] shortcode via a comment_text filter hook, allowing unauthenticated visitors who can post comments to supply a malicious shortcode argument that persists in the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 106-24
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-10092 (CVSS 7.2) Cincopa WordPress plugin vulnerable to Stored XSS via shortcode in comments. Unauthenticated attackers can inject malicious scripts. Affected: All versions ≤1.163 Patch immediately. #CVE #WordPress #PatchNow https://t.co/MpVRXBtby1

    Post summary

    Cincopa WordPress plugin CVE-2026-10092 is a stored XSS vulnerability (CVSS 7.2) affecting all versions ≤1.163; users are advised to patch immediately.

    0000030
    50 followersView on X

Explore more