CVE-2026-88905 - KeyWord Collector <= 1.4 - Unauthenticated Stored XSS and Settings Update via WPKeyWordSettings
CVE ID :CVE-2026-88905 Published : Oct. 11, 2026, 7:17 a.m. | 6 hours, 13 minutes ago Description :The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated...