CVE-2026-105060: WordPress Logo Showcase plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Themepoints Logo Showcaseto a version that resolves this vulnerability.Fixed in 4.0.5
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and that user interaction is required. The attack can be carried out remotely over the network and has low attack complexity.
What is the potential impact if exploitation succeeds?
Successful exploitation can result in low impact to confidentiality, integrity, and availability, with the impact extending beyond the vulnerable security authority. The issue is rated medium severity with a CVSS score of 6.5.