CVE-2026-1187 | ZoomifyWP Free Plugin up to 1.1 on WordPress Shortcode zoomify filename cross site scripting
A vulnerability classified as problematic was found in ZoomifyWP Free Plugin up to 1.1 on WordPress. Affected is the function zoomify of the component Shortcode Handler. Executing a manipulation of the argument filename can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-1187. The attack can be launched remotely. No exploit exists.