
CVE-2026-1647 The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1… https://www.cve.org/CVERecord?id=CVE-2026-1647
Post summary
CVE-2026-1647 is a reflected cross‑site scripting flaw in the Comment Genius WordPress plugin affecting all versions up to 1.x, with no PoC, exploit code, patch, or active exploitation mentioned.
