CVE-2026-28110: WordPress LambertGroup - AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist all-in-one-bannerWithPlaylist allows Reflected XSS.This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a through <= 3.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28110?
The severity of CVE-2026-28110 is classified as medium due to its impact on user data and potential for exploitation via XSS.
How do I fix CVE-2026-28110?
To fix CVE-2026-28110, update the LambertGroup - AllInOne - Banner with Playlist plugin to version 3.9 or later.
What type of vulnerability is CVE-2026-28110?
CVE-2026-28110 is a Reflected Cross Site Scripting (XSS) vulnerability that occurs due to improper neutralization of input during web page generation.
Who is affected by CVE-2026-28110?
Users of the LambertGroup - AllInOne - Banner with Playlist plugin versions 3.8 and earlier on WordPress are affected by CVE-2026-28110.
Can CVE-2026-28110 lead to data theft?
Yes, CVE-2026-28110 could potentially lead to data theft if an attacker successfully exploits the XSS vulnerability to execute malicious scripts.