CVE-2026-27420: WordPress Zotpress plugin <= 7.4.4 - Cross Site Scripting (XSS) vulnerability
Published Oct 8, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Seaborn Zotpress zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7.4.4.
Affected Software
1 affected component
Katie Seaborn Zotpress<=7.4.4
Event History
Oct 8, 2026
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs low-level privileges and user interaction. The attack can be carried out remotely and has low attack complexity.
2
What is the expected impact if exploitation succeeds?
Successful exploitation can have low impact on confidentiality, integrity, and availability. The vulnerability has a changed scope, meaning its effects can extend beyond the initially affected security authority.