WordPress List Site Contributors < 1.1.8 - Reflected XSS
CVE-2026-0594
Verified
Description
WordPress List Site Contributors plugin < 1.1.8 contains a reflected XSS caused by insufficient sanitization and escaping of the 'alpha' parameter, letting unauthenticated attackers inject scripts, exploit requires user interaction.
Severity
Medium
Published Date
January 23, 2026
Template Author
m4sh_wacker
CVE-2026-0594.yaml
Remediation Steps
Update to a version later than 1.1.8 or the latest available version.