CVE-2026-8698
The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the as_get_coin_shortcode() function, which renders the ‘width’ (and ‘height’) shortcode attribute directly into the style attribute of an
More information : https://plugins.trac.wordpress.org/browser/cryptocurrency-prijsvergelijking-widget/trunk/functions.php#L138
