
CVE-2026-3600 The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-years' attribute in all… https://www.cve.org/CVERecord?id=CVE-2026-3600
Post summary
The Investi WordPress plugin contains a stored XSS flaw via the maximum-num-years attribute; no exploit, patch, or active use is reported.

