
CVE-2026-2121 The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in all versions up to, and including, 1.8.1. This … https://www.cve.org/CVERecord?id=CVE-2026-2121
Post summary
The brief notice announces CVE‑2026‑2121 as a stored XSS vulnerability in the Weaver Show Posts WordPress plugin before v1.8.1, without providing any PoC, exploit code, or patch details.
