CVE-2026-82123: WordPress Loops & Logic - Reflected XSS
Published Aug 28, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic.
Affected Software
1 affected component
WordPress Loops & Logic
Event History
Aug 28, 2026
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates that the issue is network-reachable and can be exploited without privileges or user interaction.
2
What impact is indicated if the vulnerability is exploited?
The reported CVSS metrics indicate low confidentiality and low integrity impact, with no availability impact.