CVE-2026-5715 | scui2 Voyage Plus Plugin up to 1.0.6 on WordPress Shortcode post-content Class cross site scripting
A vulnerability categorized as problematic has been discovered in scui2 Voyage Plus Plugin up to 1.0.6 on WordPress. This affects the function post-content of the component Shortcode Handler. The manipulation of the argument Class results in cross site scripting.
This vulnerability was named CVE-2026-5715. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.