Multiple WordPress and web plugin XSS vulnerabilities disclosed

Five cross-site scripting (XSS) vulnerabilities were disclosed across WordPress plugins and web libraries between July 22–28, 2026, with one involving Microsoft OWA already weaponized by threat actors. Severity ranges from standard XSS to stored and reflected variants.

5 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-14870 - Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id

stream:bsky-jetstreamother63d ago kagi ↗

CVE-2026-14870 - Database for Contact Form 7, WPforms, Elementor forms CVE ID : CVE-2026-14870 Published : July 28, 2026, 6 a.m. | 1 hour, 25 minutes ago Description : The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not proper... The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape

CVE-2026-17528 - nice-select2 Cross-site Scripting Vulnerability

stream:bsky-jetstreamother63d ago kagi ↗

CVE-2026-17528 - nice-select2 Cross-site Scripting Vulnerability CVE ID : CVE-2026-17528 Published : July 28, 2026, 6:16 a.m. | 1 hour, 8 minutes ago Description : Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the elem... Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker c

CVE-2026-66919 - Stored DOM-Based Cross-Site Scripting in Node Modal Headers

stream:bsky-jetstreamother63d ago kagi ↗

CVE-2026-66919 - Stored DOM-Based Cross-Site Scripting in Node Modal Headers CVE ID : CVE-2026-66919 Published : July 28, 2026, 1:19 p.m. | 1 hour, 21 minutes ago Description : Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. No... Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions orig

The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having bee

mastodon:infosec-exchangeother61d ago kagi ↗

The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. https:// thehackernews.com/2026/07/russ ian-hackers-exploit-microsoft-owa.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33l5