CVE-2026-101928 | MagicPlugins Magic Tooltips for Contact Form 7 Plugin up to 1.0.34 on WordPress Escaping edit-comments.php esc_html author cross site scripting

SecurityVulns

A vulnerability categorized as problematic has been discovered in MagicPlugins Magic Tooltips for Contact Form 7 Plugin up to 1.0.34 on WordPress. This issue affects the function esc_html of the file wp-admin/edit-comments.php of the component Escaping. The manipulation of the argument Author results in cross site scripting.

This vulnerability is cataloged as CVE-2026-101928. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More