Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp Magnific Popup Wp Magnific Popup wp Magnific Popup |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp Magnific Popup Wp Magnific Popup wp Magnific Popup |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Wed, 17 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 17 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user. | |
| Title | WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-17T10:48:01.172Z
Reserved: 2026-05-05T11:15:08.498Z
Link: CVE-2026-7850
Updated: 2026-06-17T10:47:56.354Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:42:31Z