CVE-2026-84279

CVE-2026-84279 published: The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for...

View full NVD advisory → ← Back to CVE watch