CVE-2026-104396: WordPress Name Directory plugin <= 1.34.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory allows Stored XSS.This issue affects Name Directory: from n/a through 1.34.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Name Directory pluginto a version that resolves this vulnerability.Fixed in 1.34.3
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates an attacker needs low-level privileges and user interaction. The attack can be performed over the network with low attack complexity.
What is the impact if exploitation succeeds?
This is a stored XSS issue, meaning injected script can be retained and later execute when another user views affected content. The CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed.
Which versions are affected?
Name Directory versions through 1.34.2 are affected. The provided data does not identify a fixed version.