plugin

Cm Custom Reports Vulnerabilities

4 known security issues reported for the Cm Custom Reports WordPress plugin. Most recent disclosed Mar 20, 2026.

1 high 3 medium

Running Cm Custom Reports on your site? Check whether your installed version is affected.

Scan your site free

CM Custom WordPress Reports and Analytics - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels vulnerability

medium

Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels vulnerability

CVSS:
5.9
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Mar 20, 2026

CM Custom Reports <= 1.2.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels

medium

The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admi...

CVSS:
4.4
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Mar 19, 2026

CVE-2026-2432 on NVD →

CM Custom WordPress Reports and Analytics - Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters vulnerability

high

Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters vulnerability

CVSS:
7.1
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Mar 9, 2026

CM Custom Reports <= 1.2.7 - Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters

medium

The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

CVSS:
6.1
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Mar 6, 2026

CVE-2026-2431 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database