WordPress security by component
Child Pages Card
Plugin description
Child Pages Card is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 5.4.
Plugin slug:
child-pages-cardLatest vulnerability
CVE-2026-18395: Child Pages Card color shortcode attribute permits Contributor stored XSS
Child Pages Card before 1.09 allows a Contributor or higher role to store an attacker-controlled color attribute in the childpagescard shortcode. childpagescard_func() accepts the value through shortcode_atts(), passes it to childpagescard() and inserts it without escaping into the card's border-left style attribute. Rendering the stored post can therefore break the HTML attribute and execute script in a visitor's WordPress origin. The CNA does not disclose the demonstrated payload or victim role.
| Safe version |
|
||
|---|---|---|---|
| Aug 06, 2026 |
CVE-2026-18395
Child Pages Card color shortcode attribute permits Contributor stored XSS
Child Pages Card before 1.09 allows a Contributor or higher role to store an attacker-controlled color attribute in the childpagescard shortcode. childpagescard_func() accepts the value through shortcode_atts(), passes it to childpagescard() and inserts it without escaping into the card's border-left style attribute. Rendering the stored post can therefore break the HTML attribute and execute script in a visitor's WordPress origin. The CNA does not disclose the demonstrated payload or victim role.
|
1.09 |
CVE5.4
NVDPending
|