CVE · Medium

CVE-2026-39483 — VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.113.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39483 VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.113.4 Medium 6.5 < 9.113.4 9.113.4 2026-03-23

CVE-2026-39483

A WordPress plugin called VK All in One Expansion Unit has a security flaw that allows attackers to inject malicious code into website pages. This vulnerability occurs because the plugin doesn't properly filter out and escape user input, making it possible for attackers to inject JavaScript code that will run when a user visits the affected page, even if the user is not logged in. The attacker must have contributor-level access or higher to exploit this flaw.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.