
CVE-2026-7475 The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to, and including, 3.3… https://www.cve.org/CVERecord?id=CVE-2026-7475
Post summary
The CVE‑2026‑7475 unpatched Sky Addons plugin is vulnerable to stored XSS through the sky‑custom‑scripts post type up to version 3.3.

