
For those wondering, with CVE-2026-8871 / CVE-2026-8872, there's a file at https[:]//host.com/epa/scripts/linux/nsepa.deb If the file is 11230664 bytes, it's unpatched. If the file is 10688726 bytes, it's patched. If the file is missing - No clue :p
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'window', 'class', and 'label') in the FrmKinetic::link() function, which are concatenated directly into HTML attributes of an anchor tag. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

For those wondering, with CVE-2026-8871 / CVE-2026-8872, there's a file at https[:]//host.com/epa/scripts/linux/nsepa.deb If the file is 11230664 bytes, it's unpatched. If the file is 10688726 bytes, it's patched. If the file is missing - No clue :p