CVE-2026-96450: WordPress pixfort Core plugin < 4.3.3 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
Affected Software
1 affected component
pixfort pixfort Core plugin<4.3.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress pixfort Core pluginto a version that resolves this vulnerability.Fixed in 4.3.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
The vulnerability is described as contributor-level XSS, so exploitation requires contributor access to a site using an affected pixfort Core plugin version.
2
What conditions are required for exploitation?
The CVSS vector indicates network access, low attack complexity, low privileges, and user interaction are required. An attacker must be able to submit the malicious content and a user must interact with it.
3
Which versions need remediation?
pixfort Core versions earlier than 4.3.3 are affected. Update the plugin to version 4.3.3 or later.