CVE-2026-9271 Details
Description
Vulnerability Title
A stored cross-site scripting vulnerability has been identified in the KeepInMind - Dashboard Notes WordPress plugin, affecting versions prior to 0.8.4.2. This vulnerability allows low-privileged users, such as Contributors, to inject malicious payloads via the REST API. The injected scripts execute when an Administrator views the dashboard, potentially leading to unauthorized access of administrative accounts. Additionally, this vulnerability causes a persistent denial-of-service condition on the administrative interface by overlaying a fake 'Session Expired' prompt, blocking access to essential management functions.
Users are advised to update to KeepInMind - Dashboard Notes version 0.8.4.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/b5d549b7-17c8-417d-a86a-a7ae356a6eab/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| KeepInMind Dashboard Notes | <= 0.8.2.9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion