A vulnerability, which was classified as problematic, has been found in dartiss ShareOpenly Plugin up to 1.2.0 on WordPress. Affected by this issue is the function esc_url. Performing a manipulation of the argument url results in cross site scripting. This vulnerability was named CVE-2026-48094. The attack may be initiated remotely. There is no... Weiterlesen: CVE-2026-48094 | dartiss ShareOpenly Plugin up to 1.2.0 on WordPress …
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-48094 | dartiss ShareOpenly Plugin up to 1.2.0 on WordPress esc_url cross site scripting
A vulnerability, which was classified as problematic, has been found in dartiss ShareOpenly Plugin up to 1.2.0 on WordPress. Affected by this issue is the…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2026-48094
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-08-07T15:09:45.472456Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com