
CVE-2026-1047 The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 d… https://www.cve.org/CVERecord?id=CVE-2026-1047
Post summary
A stored XSS vulnerability exists in the Salavat Counter WordPress plugin up to version 0.9.5, affecting the image_url parameter; no PoC, exploit, or mitigation details are included.
