关键漏洞信息 CVE ID: - CVE-2026-1164 CVSS Score: - 6.1 (Medium) Publicly Published: - February 13, 2026 Last Updated: - February 14, 2026 Vulnerability Type: - Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Description: - The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This allows authenticated attackers with Administrator-level access and above to inject arbitrary web scripts in pages that execute when a user accesses an injected page. Affected Software: - Easy Voice Mail (easy-voice-mail) versions <= 1.2.5 Researcher: - Kazuma Matsumoto - GMO Cybersecurity by IERAE, Inc. Patch Available: - No Remediation: - No known patch available. Consider uninstalling the affected software and finding a replacement based on your organization's risk tolerance. Reference: - plugins.trac.wordpress.org