
CVE-2026-1634 The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including… https://www.cve.org/CVERecord?id=CVE-2026-1634
Post summary
The statement announces a Reflected XSS vulnerability in the Subitem AL Slider WordPress plugin, providing basic technical details but no PoC, exploit code, or patch information.
