CVE-2026-92411

CVE-2026-92411 published: The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags,...

View full NVD advisory → ← Back to CVE watch