
CVE-2026-2506 The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing atta… https://www.cve.org/CVERecord?id=CVE-2026-2506
Post summary
The EM Cost Calculator plugin for WordPress is vulnerable to stored XSS in versions up to 2.3.1, as disclosed in CVE-2026-2506.
