CVE-2026-1854 | nosoycesaros Post Flagger Plugin up to 1.1 on WordPress Shortcode flag cross site scripting
A vulnerability marked as problematic has been reported in nosoycesaros Post Flagger Plugin up to 1.1 on WordPress. This affects the function flag of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-1854. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.