← WordPress Vulnerabilities
WordPress security by component

WP Highlight Box

WP Highlight Box (wp-highlight-box) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 6.8.

Plugin slug: wp-highlight-box

CVE-2026-86790: WP Highlight Box shortcode attributes permit stored XSS

WP Highlight Box through 1.0 outputs some shortcode attributes without escaping them. A contributor or higher role can place attacker-controlled markup in a page containing the shortcode, causing JavaScript to execute when the page is viewed. The authoritative export does not identify the shortcode tag, affected attributes, or output contexts.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wp-highlight-box
Safe version
Sep 12, 2026 CVE-2026-86790
WP Highlight Box shortcode attributes permit stored XSS
WP Highlight Box through 1.0 outputs some shortcode attributes without escaping them. A contributor or higher role can place attacker-controlled markup in a page containing the shortcode, causing JavaScript to execute when the page is viewed. The authoritative export does not identify the shortcode tag, affected attributes, or output contexts.
See mitigation notes
CVE6.8
NVDPending