CVEFinder.io

CVE-2026-81404

⚠️ high
🔍 Scan for this CVE
Summary

The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.

CVSS Score
7.1
High
EPSS Score
0.2
Exploit Probability
Published Date
2026-09-05
First Seen: 2026-09-06
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 52.3% of all 353,175 vulnerabilities in our database.

#168,494
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Sep 6, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Vuln Seeker Cyber Security Team WPScan (coordinator)
SSVC data provided by CISA
Last Modified 2026-09-06
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CWE IDs (Weakness Types)

📦 Affected Products 0

No affected products information available

🔗 References 1