
CVE-2026-5506 The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all versions up to, and including, 0.2.6. This is due to… https://www.cve.org/CVERecord?id=CVE-2026-5506
Post summary
The Wavr WordPress plugin is publicly disclosed to have a stored XSS vulnerability (CVE-2026-5506) affecting all versions up to 0.2.6, as noted in the linked CVE record.

