CVE-2026-85679 | Extendify Plugin up to 3.1.6 on WordPress Block Type Key /wp/v2/global-styles registerIncoming styles.blocks cross site scripting
A vulnerability, which was classified as problematic, has been found in Extendify Plugin up to 3.1.6 on WordPress. This affects the function registerIncoming of the file /wp/v2/global-styles of the component Block Type Key. Performing a manipulation of the argument styles.blocks results in cross site scripting.
This vulnerability is reported as CVE-2026-85679. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More