CVE-2026-24555Cross-site Scripting in Widget

Severity
6.1MEDIUMNVD
EPSS
0.0%
top 88.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 23

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Stored XSS.This issue affects ArtPlacer Widget: from n/a through <= 2.23.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

CVEListV5artplacer/artplacer_widget2.23.2

🔴Vulnerability Details

2
CVEList
WordPress ArtPlacer Widget plugin <= 2.23.2 - Cross Site Scripting (XSS) vulnerability2026-01-23
GHSA
GHSA-q5rh-rhr2-9pqq: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artplacer ArtPlacer Widget artplacer-widget allo2026-01-23

🕵️Threat Intelligence

1
Wiz
CVE-2026-24555 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-24555 — Cross-site Scripting in Widget | cvebase