
CVE-2026-2489 The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all … https://www.cve.org/CVERecord?id=CVE-2026-2489
Post summary
The TP2WP Importer plugin for WordPress is disclosed to have a stored XSS vulnerability in the 'Watched domains' textarea, as identified by CVE-2026-2489.
