
CVE-2026-1912 The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'ctdoi' shortcode in all versions up to, and inclu… https://www.cve.org/CVERecord?id=CVE-2026-1912
Post summary
The text reports CVE‑2026‑1912, a stored XSS vulnerability in the Citations tools WordPress plugin affecting the 'code' parameter of the 'ctdoi' shortcode.


