CVE-2026-8790 - Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting
CVE ID :CVE-2026-8790
Published : Aug. 5, 2026, 6:16 a.m. | 38 minutes ago
Description :The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `
Published : Aug. 5, 2026, 6:16 a.m. | 38 minutes ago
Description :The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `