
CVE-2026-1985 The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all versions up to, and including, 1.0.2. This is due … https://www.cve.org/CVERecord?id=CVE-2026-1985
Post summary
Press3D WordPress plugin is vulnerable to stored XSS up to version 1.0.2; no PoC, patch, or exploitation details are provided.

