CVE-2026-0693 | Allow HTML in Category Descriptions Plugin up to 1.2.4 on WordPress wp_kses_data cross site scripting
A vulnerability categorized as problematic has been discovered in Allow HTML in Category Descriptions Plugin up to 1.2.4 on WordPress. This issue affects the function wp_kses_data. Executing a manipulation of the argument term_description/link_description/link_notes/user_description can lead to cross site scripting.
This vulnerability is handled as CVE-2026-0693. The attack can be executed remotely. There is not any exploit available.