
CVE-2026-4067 The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. Th… https://www.cve.org/CVERecord?id=CVE-2026-4067
Post summary
Ad Short plugin for WordPress is disclosed to have a stored XSS vulnerability via the 'client' attribute of its ad shortcode.

