WordPress List Site Contributors plugin < 1.1.8 contains a reflected XSS caused by insufficient sanitization and escaping of the 'alpha' parameter, letting unauthenticated attackers inject scripts, exploit requires user interaction.
id: CVE-2026-0594
info:
name: WordPress List Site Contributors < 1.1.8 - Reflected XSS
author:
...