CVE-2026-8895 | kenz60 kk blog card Plugin up to 1.3 on WordPress kk-blog-card-shortcode.php href/type cross site scripting
A vulnerability described as problematic has been identified in kenz60 kk blog card Plugin up to 1.3 on WordPress. This vulnerability affects unknown code of the file kk-blog-card-shortcode.php. Such manipulation of the argument href/type leads to cross site scripting.
This vulnerability is documented as CVE-2026-8895. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.