
CVE-2026-1071 The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.13.0 due to insufficient i… https://www.cve.org/CVERecord?id=CVE-2026-1071
Post summary
The post announces CVE-2026-1071, a stored XSS flaw in the Carta Online WordPress plugin affecting versions up to 2.13.0. No exploitation details, PoC, or patch are provided.

