
CM Custom Reports plugin: Stored XSS (CVE-2026-2432). Admin input not sanitized, outputs raw. CVSS 4.4. Multi-site risk. No patch. Basic DevSecOps failure. #WordPress #XSS #CodeQuality #CVE #Developers #Hosting #CyberSecurity #infosec Info: https://www.valtersit.com/cve/2026/03/cve-2026-2432/
Post summary
This tweet announces a stored XSS vulnerability (CVE‑2026‑2432) in the CM Custom Reports WordPress plugin, notes the lack of a patch, and provides basic technical details but no PoC or exploit code.

