
CVE-2026-1278 The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.8 due to insufficient… https://www.cve.org/CVERecord?id=CVE-2026-1278
Post summary
The Mandatory Field plugin for WordPress is reported to be vulnerable to stored XSS via admin settings in all versions up to 1.6.8, with no PoC, exploit, or patch details disclosed.
