
CVE-2026-1164 The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 1.2.5 due to ins… https://www.cve.org/CVERecord?id=CVE-2026-1164
Post summary
CVE‑2026‑1164 discloses a stored XSS flaw in Easy Voice Mail plugin up to version 1.2.5, triggered via the ‘message’ parameter.


