Vulnerability Description
The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and including, 1.163 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation is possible because the plugin processes the [cincopa] shortcode via a comment_text filter hook, allowing unauthenticated visitors who can post comments to supply a malicious shortcode argument that persists in the database.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/video-playlist-and-gallery-plugin/tag
- https://plugins.trac.wordpress.org/browser/video-playlist-and-gallery-plugin/tag
- https://plugins.trac.wordpress.org/browser/video-playlist-and-gallery-plugin/tag
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2d6304e5-7fbf-484d-b14
FAQ
What is CVE-2026-10092?
CVE-2026-10092 is a vulnerability with a CVSS score of 7.2 (HIGH). The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and including, 1.163 due to insuffic...
How severe is CVE-2026-10092?
CVE-2026-10092 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10092?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.