
CVE-2026-5717 Stored Cross-Site Scripting in VI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5717
Post summary
The post announces CVE-2026-5717, a stored XSS vulnerability in VI, and provides a link for further details.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in all versions up to, and including, 0.4.200706 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-5717 Stored Cross-Site Scripting in VI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5717
Post summary
The post announces CVE-2026-5717, a stored XSS vulnerability in VI, and provides a link for further details.

CVE-2026-5717 The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in … https://www.cve.org/CVERecord?id=CVE-2026-5717
Post summary
The snippet announces that the Include Post By plugin for WordPress contains a stored XSS flaw triggered through the 'class_container' attribute, presenting a detailed vulnerability description without implying active exploitation or a PoC.