N/A Unfixed Closed 2026-02-10≤ 2.0 Category Image <= 2.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'tag-image' Parameter WordfenceCVE