
CVE-2026-1823 The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortcode in all versions up to, and including, 1.6 due… https://www.cve.org/CVERecord?id=CVE-2026-1823
Post summary
The post announces CVE‑2026‑1823, noting that the Consensus Embed WordPress plugin up to version 1.6 is vulnerable to stored XSS through its consensus shortcode.

