CVE-2026-1647 | basiliskan Comment Genius Plugin up to 1.2.5 on WordPress Parameters $_SERVER['PHP_SELF'] cross site scripting
A vulnerability marked as problematic has been reported in basiliskan Comment Genius Plugin up to 1.2.5 on WordPress. Affected is an unknown function of the component Parameters Handler. This manipulation of the argument $_SERVER['PHP_SELF'] causes cross site scripting.
This vulnerability appears as CVE-2026-1647. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.