
CVE-2026-2431 The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and inclu… https://www.cve.org/CVERecord?id=CVE-2026-2431
Post summary
A disclosure of a reflected XSS flaw in the CM Custom Reports plugin for WordPress, affecting all versions up to the mentioned date.
