
CVE-2026-3353 The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in all versions up to, and including, 1.2.1. This is … https://www.cve.org/CVERecord?id=CVE-2026-3353
Post summary
The text announces a Stored XSS vulnerability in the Comment SPAM Wiper WordPress plugin, detailing the affected versions and the vulnerable API key setting.

