Skip to main content
Loading…
    CVE-2026-4005 — The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insuffi — CVE Database · The Intelligence Room