Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
Lawyer Directory Input Not Sanitized, Allows Malicious Code Injection
CVE-2026-28127
Summary
The Lawyer Directory plugin for WordPress has a security flaw that can let hackers inject malicious code into web pages, potentially stealing user data or taking control of user sessions. This affects versions up to 1.3.2. To stay safe, update to the latest version of the plugin.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Dire...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Directory: from n/a through <= 1.3.2.
nvd CVSS3.1
7.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026