
CVE-2026-2498 The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient … https://www.cve.org/CVERecord?id=CVE-2026-2498
Post summary
The WP Social Meta plugin for WordPress is vulnerable to stored XSS via admin settings in all versions up to 1.0.1, as documented in CVE-2026-2498.

