
CVE-2026-2434 The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 … https://www.cve.org/CVERecord?id=CVE-2026-2434
Post summary
The text announces a stored XSS vulnerability (CVE‑2026‑2434) in the Pz‑LinkCard WordPress plugin, detailing impacted versions but providing no exploit or patch information.
