
CVE-2026-1275 The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' shortcode attribute in all versions up to, and in… https://www.cve.org/CVERecord?id=CVE-2026-1275
Post summary
The Multi Post Carousel by Category plugin for WordPress is exposed to a stored XSS vulnerability through its 'slides' shortcode, affecting all versions listed under CVE-2026-1275.
