
CVE-2026-1401 The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficie… https://www.cve.org/CVERecord?id=CVE-2026-1401
Post summary
CVE-2026-1401 announces that the Tune Library WordPress plugin is vulnerable to stored cross‑site scripting via CSV import in all versions up to 1.6.3.

