CVE-2026-42631: WordPress Qode Music plugin <= 2.1.8.2 - Cross Site Scripting (XSS) vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions.
Affected Software
1 affected component
Qode Qode Music<=2.1.8.2
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What versions are affected?
Qode Music versions 2.1.8.2 and earlier are affected.
2
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need to log in before attempting exploitation.
3
Does exploitation require user interaction?
Yes. The provided CVSS vector includes UI:R, indicating that exploitation requires user interaction.