CVE-2026-1853 | BuddyHolis ListSearch Plugin up to 1.1 on WordPress Shortcode placeholder cross site scripting
A vulnerability was found in BuddyHolis ListSearch Plugin up to 1.1 on WordPress. It has been rated as problematic. The impacted element is an unknown function of the component Shortcode Handler. Performing a manipulation of the argument placeholder results in cross site scripting.
This vulnerability is cataloged as CVE-2026-1853. It is possible to initiate the attack remotely. There is no exploit available.