
CVE-2026-4852 The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment fiel… https://www.cve.org/CVERecord?id=CVE-2026-4852
Post summary
The text announces a newly identified stored XSS vulnerability in the WordPress plugin 'Image Source Control Lite – Show Image Credits and Captions', specifying the flaw but providing no PoC, exploit code, patch, or evidence of active exploitation.
