CVE-2026-11778 | villatheme CURCY Plugin up to 2.2.14 on WordPress Shortcode code injection
A vulnerability classified as critical has been found in villatheme CURCY Plugin up to 2.2.14 on WordPress. This affects an unknown part of the component Shortcode Handler. This manipulation causes code injection.
This vulnerability is handled as CVE-2026-11778. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More