What is CVE-2026-15002?
The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook. Users should update the plugin to the latest version immediately.
Azərbaycanca: WordPress üçün Platnosci Online Blue Media (Autopay) plaqini 5.0.0-a qədər versiyalarda 'bm_woocommerce_css_editor_content' POST parametri vasitəsilə Stored Cross-Site Scripting zəifliyinə məruz qalır. Bu, Css_Editor::handle_save() metodunun WordPress 'init' hookuna qoşulması səbəbindən baş verir. İstifadəçilər plaqini mümkün ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Blue Media plugin are vulnerable to the Stored XSS?
The Platnosci Online Blue Media (Autopay) plugin is vulnerable in versions up to and including 5.0.0.
Which POST parameter is used to exploit this vulnerability?
The vulnerability is exploited via the 'bm_woocommerce_css_editor_content' POST parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.