Report: CVE-2026-3997 - Text Toggle <= 1.1 - authenticated (contributor+) stored cross-site scripting via...
CVE ID :CVE-2026-3997 Published : March 21, 2026, 3:27 a.m. | 1 hour ago Description :The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] shortcodes in all versions up to and including 1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, in the avp_texttoggle_part_shortcode() function, the 'title' attribute is extracted from shortcode attributes and concatenated directly into HTML output without any escaping — both within an HTML attribute context (title=