WordPress security by component
WP Highlight Box
WP Highlight Box (wp-highlight-box) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 6.8.
Plugin slug:
wp-highlight-boxLatest vulnerability
CVE-2026-86790: WP Highlight Box shortcode attributes permit stored XSS
WP Highlight Box through 1.0 outputs some shortcode attributes without escaping them. A contributor or higher role can place attacker-controlled markup in a page containing the shortcode, causing JavaScript to execute when the page is viewed. The authoritative export does not identify the shortcode tag, affected attributes, or output contexts.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-86790
WP Highlight Box shortcode attributes permit stored XSS
WP Highlight Box through 1.0 outputs some shortcode attributes without escaping them. A contributor or higher role can place attacker-controlled markup in a page containing the shortcode, causing JavaScript to execute when the page is viewed. The authoritative export does not identify the shortcode tag, affected attributes, or output contexts.
|
See mitigation notes |
CVE6.8
NVDPending
|