CVE-2026-6690 | ashanjay LifePress Plugin up to 2.2.2 on WordPress Setting wp_ajax_nopriv_lp_update_mds cross site scripting
A vulnerability described as problematic has been identified in ashanjay LifePress Plugin up to 2.2.2 on WordPress. The affected element is the function wp_ajax_nopriv_lp_update_mds of the component Setting Handler. Executing a manipulation of the argument n can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-6690. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.