CVE-2026-1824 | Infomaniak Connect for OpenID Plugin up to 1.0.2 on WordPress Shortcode infomaniak_connect_generic_auth_url endpoint_login cross site scripting
A vulnerability, which was classified as problematic, has been found in Infomaniak Connect for OpenID Plugin up to 1.0.2 on WordPress. This vulnerability affects the function infomaniak_connect_generic_auth_url of the component Shortcode Handler. Performing a manipulation of the argument endpoint_login results in cross site scripting.
This vulnerability is cataloged as CVE-2026-1824. It is possible to initiate the attack remotely. There is no exploit available.