CVE-2026-1866 | Name Directory Plugin up to 1.32.0 on WordPress html_entity_decode name_directory_name/name_directory_description cross site scripting
A vulnerability classified as problematic has been found in Name Directory Plugin up to 1.32.0 on WordPress. This affects the function html_entity_decode. This manipulation of the argument name_directory_name/name_directory_description causes cross site scripting.
This vulnerability is tracked as CVE-2026-1866. The attack is possible to be carried out remotely. No exploit exists.