CVE-2026-1098 | CM CSS Columns Plugin up to 1.2.1 on WordPress Shortcode day cross site scripting (EUVD-2026-4562)
A vulnerability was found in CM CSS Columns Plugin up to 1.2.1 on WordPress. It has been rated as problematic. The affected element is an unknown function of the component Shortcode Handler. The manipulation of the argument day leads to cross site scripting.
This vulnerability is referenced as CVE-2026-1098. Remote exploitation of the attack is possible. No exploit is available.