Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.4
Infomaniak Connect for OpenID plugin allows attackers to inject malicious scripts
CVE-2026-1824
Summary
The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to a security threat that allows attackers to inject malicious scripts into web pages. This can happen if an attacker with contributor-level access or higher edits a page and includes a specific code snippet. To protect your website, update the plugin to the latest version.
Original title
The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_login' parameter of the infomaniak_connect_generic_auth_url shortcode in all ve...
Original description
The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_login' parameter of the infomaniak_connect_generic_auth_url shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
nvd CVSS3.1
6.4
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 7 Mar 2026 · Updated: 13 Mar 2026 · First seen: 7 Mar 2026