CVE-2026-24983: WordPress UpSolution Core plugin <= 8.41 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from n/a through <= 8.41.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24983?
The severity of CVE-2026-24983 is considered critical due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2026-24983?
To fix CVE-2026-24983, update the UpSolution Core plugin to version 8.42 or later.
What types of attacks can CVE-2026-24983 facilitate?
CVE-2026-24983 can facilitate reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Who is affected by CVE-2026-24983?
CVE-2026-24983 affects users of UpSolution Core plugin version 8.41 and earlier.
What should I do if I cannot update the UpSolution Core plugin for CVE-2026-24983?
If you cannot update the UpSolution Core plugin, consider disabling the plugin temporarily and applying input sanitization measures.