{"id":"CVE-2026-86790","title":"The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored C…","summary":"The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored C…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79"],"product":"WP Highlight Box","affected":["wp_highlight_box <= 1.0"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86790","references":[{"url":"https://wpscan.com/vulnerability/b48571ae-368e-4193-977a-f22fb09db4d4/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00235,"epssPercentile":0.14793,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-12T15:18:23.221660Z"},"ingestedAt":"2026-09-14T15:23:07.479Z","slug":"CVE-2026-86790","body":"## Overview\n\nThe WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}