CVE-2026-11778 | villatheme CURCY Plugin up to 2.2.14 on WordPress Shortcode code injection

SecurityVulns

A vulnerability classified as critical has been found in villatheme CURCY Plugin up to 2.2.14 on WordPress. This affects an unknown part of the component Shortcode Handler. This manipulation causes code injection.

This vulnerability is handled as CVE-2026-11778. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More