PT-2026-42082 · WordPress · Lj Comments Import: Reloaded

Abdulsamad Yusuf

·

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-8624

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LJ comments import: reloaded versions prior to 0.97.2
Description The LJ comments import: reloaded plugin for WordPress contains a Reflected Cross-Site Scripting issue caused by insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts into pages by tricking a user into clicking a link. This occurs because the PHP SELF parameter includes attacker-controllable PATH INFO appended to the script name, which is then processed through two unsanitized echo points within the same function.
Recommendations Update to a version later than 0.97.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-8624

Affected Products

Lj Comments Import: Reloaded