
For those wondering, with CVE-2026-8871 / CVE-2026-8872, there's a file at https[:]//host.com/epa/scripts/linux/nsepa.deb If the file is 11230664 bytes, it's unpatched. If the file is 10688726 bytes, it's patched. If the file is missing - No clue :p
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes in the shortcode_args_to_html_attrs() function, which concatenates shortcode attribute values directly into double-quoted HTML attributes without calling esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

For those wondering, with CVE-2026-8871 / CVE-2026-8872, there's a file at https[:]//host.com/epa/scripts/linux/nsepa.deb If the file is 11230664 bytes, it's unpatched. If the file is 10688726 bytes, it's patched. If the file is missing - No clue :p