
CVE-2026-2358 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and… https://www.cve.org/CVERecord?id=CVE-2026-2358
Post summary
The post announces a new CVE‑2026‑2358 affecting the WP ULike WordPress plugin, detailing a stored XSS issue in the shortcode’s template attribute.
