
CVE-2026-5341 The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and i… https://www.cve.org/CVERecord?id=CVE-2026-5341
Post summary
The NMR Strava activities plugin for WordPress has been disclosed as vulnerable to stored XSS via its shortcode, affecting all versions up to the current release.

