Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arieslab
Arieslab press3d Wordpress Wordpress wordpress |
|
| Vendors & Products |
Arieslab
Arieslab press3d Wordpress Wordpress wordpress |
Sat, 14 Feb 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all versions up to, and including, 1.0.2. This is due to the plugin failing to sanitize and validate the URL scheme when storing link URLs for 3D model blocks, allowing `javascript:` URLs. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages via the link URL parameter that will execute whenever a user clicks on the 3D model. | |
| Title | Press3D <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Link URL Parameter in 3D Model Block | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T20:39:23.597Z
Reserved: 2026-02-05T14:57:42.410Z
Link: CVE-2026-1985
Updated: 2026-02-18T20:39:19.853Z
Status : Awaiting Analysis
Published: 2026-02-14T07:16:12.320
Modified: 2026-02-18T17:52:44.520
Link: CVE-2026-1985
No data.
OpenCVE Enrichment
Updated: 2026-02-16T12:02:02Z