CVE-2026-1095 | Canto Testimonials Plugin up to 1.0 on WordPress Shortcode fx cross site scripting (EUVD-2026-4558)
A vulnerability, which was classified as problematic, was found in Canto Testimonials Plugin up to 1.0 on WordPress. Affected by this issue is the function fx of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-1095. It is possible to launch the attack remotely. No exploit is available.