CVE-2026-17586 | kurudrive VK All in One Expansion Unit Plugin up to 9.118.0 on WordPress safe_kses_post vkExUnit_cta_img_position cross site scripting

SecurityVulns

A vulnerability labeled as problematic has been found in kurudrive VK All in One Expansion Unit Plugin up to 9.118.0 on WordPress. This vulnerability affects the function Vk_Call_To_Action::safe_kses_post. Executing a manipulation of the argument vkExUnit_cta_img_position can lead to cross site scripting.

This vulnerability is registered as CVE-2026-17586. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More