
CVE-2026-2277 The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters in the search-pattern tester page in all versio… https://www.cve.org/CVERecord?id=CVE-2026-2277
Post summary
The record announces a reflected XSS vulnerability in the rexCrawler WordPress plugin that affects all versions via the 'url' and 'regex' parameters on the search‑pattern tester page; no PoC, exploit code, or active exploitation is mentioned.
