Known CVE
WordPress List Site Contributors < 1.1.8 - Reflected XSS
WordPress List Site Contributors plugin < 1.1.8 contains a reflected XSS caused by insufficient sanitization and escaping of the 'alpha' parameter, letting unauthenticated attackers inject scripts, exploit requires user interaction.
CVE-2026-0594
Medium2026
cve2026 · wordpress · wp · wp-plugin · list-site-contributors · xss
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website