plugin

Twentig Vulnerabilities

2 known security issues reported for the Twentig WordPress plugin. Most recent disclosed Mar 30, 2026.

2 medium

Running Twentig on your site? Check whether your installed version is affected.

Scan your site free

Twentig Supercharged Block Editor - Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' vulnerability

medium

Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth' vulnerability

CVSS:
6.5
Affected:
up to 1.9.7
Fixed in:
2.0
Disclosed:
Mar 30, 2026

Twentig <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth'

medium

The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inj...

CVSS:
6.4
Affected:
up to 1.9.7
Fixed in:
2.0
Disclosed:
Mar 28, 2026

CVE-2026-2602 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database