CVE-2026-92967

CVE-2026-92967 published: The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2. This is due to insufficient output escaping , which reads $_GET['keyword'], applies only sanitize_text_fie...

View full NVD advisory → ← Back to CVE watch