Ghostwire

CVE-2026-12980: The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets...

MEDIUM CVSS 0.0

Published: October 11, 2026 | Last Modified: October 11, 2026

Description

The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References