CVE-2026-102378: WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Parallax Section - Block pluginto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The provided data does not specify the exact input path or user interaction required.
Which installations are affected?
WordPress sites using the Parallax Section block plugin version 2.0.4 or earlier are identified as affected. The provided data does not state whether any particular plugin configuration or default setup is required.
How can I determine whether my site may be vulnerable?
Check whether the Parallax Section block plugin is installed and identify its installed version. Sites running version 2.0.4 or earlier may be affected.