CVE-2026-94158: WordPress Gloria Admin Panel plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
Gloria Admin Panel versions through 1.3 are affected. The available data does not identify a fixed version.
What must an attacker do to exploit this issue?
The vulnerability is remotely reachable and requires no attacker privileges, but it requires user interaction. Exploitation involves getting a user to interact with a crafted request or page that triggers reflected XSS.
What impact could successful exploitation have?
The issue is rated high with a 7.1 CVSS score and can affect confidentiality, integrity, and availability at low impact. Its scope is changed, indicating effects may extend beyond the vulnerable component's security authority.