
CVE-2026-1279 The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in … https://www.cve.org/CVERecord?id=CVE-2026-1279
Post summary
The CVE‑record indicates a stored XSS flaw in the Employee Directory WordPress plugin's form_title parameter, with no mention of PoC, exploit tools, active attacks, or patch status.

