CVE-2025-26887

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows Stored XSS. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.21.35.

More information : https://patchstack.com/database/wordpress/plugin/elisqlreports/vulnerability/wordpress-ez-sql-reports-shortcode-widget-and-db-backup-plugin-5-21-35-cross-site-scripting-xss-vulnerability?_s_id=cve