WordPress security by component
WP Custom HTML Page
Plugin description
WP Custom HTML Page is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 5.4.
Plugin slug:
wp-custom-html-pageLatest vulnerability
CVE-2026-16942: WP Custom HTML Page author content permits stored XSS
WP Custom HTML Page through 0.6.2 lets an Author store unsanitized HTML through a custom-page handler without requiring unfiltered_html. The plugin later serves that value unescaped at a public URL, so embedded JavaScript executes in the WordPress site origin for visitors, including administrators. This unscored record received deeper review because Author-level stored XSS can reach an administrator. The CNA does not disclose the handler, field name or public route.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-16942
WP Custom HTML Page author content permits stored XSS
WP Custom HTML Page through 0.6.2 lets an Author store unsanitized HTML through a custom-page handler without requiring unfiltered_html. The plugin later serves that value unescaped at a public URL, so embedded JavaScript executes in the WordPress site origin for visitors, including administrators. This unscored record received deeper review because Author-level stored XSS can reach an administrator. The CNA does not disclose the handler, field name or public route.
|
> 0.6.2 |
CVE5.4
NVDPending
|