
CVE-2026-4086 The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the 'wp_random_button'… https://www.cve.org/CVERecord?id=CVE-2026-4086
Post summary
The post announces that the WP Random Button WordPress plugin is vulnerable to stored XSS via specific shortcode attributes, providing technical details but no evidence of exploitation or mitigation.
