PT-2026-8079 · WordPress · Ravelry Designs Widget

Dj

+1

·

Published

2026-02-14

·

Updated

2026-02-14

·

CVE-2026-1903

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ravelry Designs Widget plugin for WordPress versions up to and including 1.0.0
Description The Ravelry Designs Widget plugin for WordPress is susceptible to Stored Cross-Site Scripting through the layout attribute of the sb ravelry designs shortcode. Insufficient input sanitization and output escaping of user-supplied attributes allow authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the affected page.
Recommendations Update the Ravelry Designs Widget plugin to a version beyond 1.0.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-1903

Affected Products

Ravelry Designs Widget