
CVE-2026-1939 The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` shortcode in all versions up to, and including, 1.… https://www.cve.org/CVERecord?id=CVE-2026-1939
Post summary
The Percent to Infograph WordPress plugin is reported to contain a stored XSS flaw triggered through the `percent_to_graph` shortcode; no PoC, exploit, or patch details are provided.

