
CVE-2026-7509 The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` attributes in all vers… https://www.cve.org/CVERecord?id=CVE-2026-7509
Post summary
The KIA Subtitle WordPress plugin is vulnerable to stored XSS via the `before` and `after` attributes of its short‑code, as documented by CVE‑2026‑7509.
