CVE-2026-68567: WordPress Convert Pro plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Convert Pro pluginto a version that resolves this vulnerability.Fixed in 1.0.2
Event History
Frequently Asked Questions
Which deployments are exposed?
Sites running the WordPress Convert Pro plugin version 1.0.1 or earlier are affected. The issue is exposed over the network and does not require the attacker to authenticate.
What does an attacker need to exploit this vulnerability?
Exploitation requires a user to interact with attacker-supplied content, as indicated by the user-interaction requirement in the severity vector. No attacker privileges are required before triggering the issue.
How can I determine whether my site is affected?
Verify the installed Convert Pro plugin version in WordPress. Versions 1.0.1 and earlier should be treated as affected based on the available information.