CVE-2026-101928

CVE-2026-101928 published: The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possibl...

View full NVD advisory → ← Back to CVE watch