PT-2026-53213 · Undefined · Undefined

Published

2026-06-29

·

Updated

2026-06-29

·

CVE-2026-10083

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another APCu Manager WordPress plugin before 4.5.0 from an unauthenticated request) are output without escaping and execute arbitrary JavaScript in the session of an administrator viewing the page.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10083

Affected Products

Undefined