The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2026-2687
NONE
Updated Mar 12, 2026
WordPress
CVE Details
CVE ID
CVE-2026-2687
Published Date
Mar 12, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory