
CVE-2026-4871 The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' attributes of the `scm_member_data` shortcode … https://www.cve.org/CVERecord?id=CVE-2026-4871
Post summary
This entry announces a stored XSS flaw in the Sports Club Management WordPress plugin, outlining the affected shortcode attributes but providing no proof of concept, exploit code, or mitigation details.
