
CVE-2026-1611 The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops` shortcode in all versions up to, and including… https://www.cve.org/CVERecord?id=CVE-2026-1611
Post summary
The Wikiloops Track Player plugin for WordPress is vulnerable to stored XSS via its shortcode in all versions, as disclosed in CVE-2026-1611.
