CVE-2026-81404: IPGP Visitors Origin < 1.6 - Reflected XSS
Published Sep 5, 2026
·Updated
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
Affected Software
1 affected component
WordPress plugin IPGP Visitors Origin<1.6
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker does not need to authenticate. Exploitation requires convincing a user to submit a crafted request that causes attacker-controlled input to be reflected in the HTTP response.
2
Which plugin versions are affected?
IPGP Visitors Origin versions earlier than 1.6 are affected. The provided information does not identify a specific fixed version beyond 1.6.