The Vigilant security plugin for WordPress version 2.10.2 and earlier is vulnerable to Stored Cross-Site Scripting via the User-Agent header, allowing unauthenticated attackers to execute arbitrary scripts in the dashboard.
The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…
xss
wordpress
cve-2026-81754
1t
1c