
CVE-2026-2281 The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is … https://www.cve.org/CVERecord?id=CVE-2026-2281
Post summary
The Private Comment plugin for WordPress suffers from a stored XSS vulnerability in the 'Label text' field across all versions up to 0.0.4. No exploit code, patch, or active exploitation details are provided.
