
CVE-2026-1901 The QuestionPro Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'questionpro' shortcode in all versions up to, and including, 1.0 due … https://www.cve.org/CVERecord?id=CVE-2026-1901
Post summary
The post announces a stored XSS vulnerability in QuestionPro Surveys plugin for WordPress, detailing the affected versions and the attack vector, but provides no evidence of exploitation, patch, or PoC.

