← WordPress Vulnerabilities
WordPress security by component

WP Custom HTML Page

WP Custom HTML Page is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 5.4.

Plugin slug: wp-custom-html-page

CVE-2026-16942: WP Custom HTML Page author content permits stored XSS

WP Custom HTML Page through 0.6.2 lets an Author store unsanitized HTML through a custom-page handler without requiring unfiltered_html. The plugin later serves that value unescaped at a public URL, so embedded JavaScript executes in the WordPress site origin for visitors, including administrators. This unscored record received deeper review because Author-level stored XSS can reach an administrator. The CNA does not disclose the handler, field name or public route.

PublishedAug 05, 2026
Known safe version> 0.6.2
Published vulnerabilities for wp-custom-html-page
Safe version
Aug 05, 2026 CVE-2026-16942
WP Custom HTML Page author content permits stored XSS
WP Custom HTML Page through 0.6.2 lets an Author store unsanitized HTML through a custom-page handler without requiring unfiltered_html. The plugin later serves that value unescaped at a public URL, so embedded JavaScript executes in the WordPress site origin for visitors, including administrators. This unscored record received deeper review because Author-level stored XSS can reach an administrator. The CNA does not disclose the handler, field name or public route.
> 0.6.2
CVE5.4
NVDPending