CVE-2026-6256 | jashjacob Credits Shortcode Plugin up to 1.2 on WordPress Link cross site scripting (beae-2803-463 / EUVD-2026-29403)
A vulnerability marked as problematic has been reported in jashjacob Credits Shortcode Plugin up to 1.2 on WordPress. Impacted is the function Credits of the component Shortcode Handler. Performing a manipulation of the argument Link results in cross site scripting.
This vulnerability is identified as CVE-2026-6256. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.