What is CVE-2026-15009?
A stored XSS vulnerability was found in the Advanced File Manager plugin for WordPress via the 'soundFile' parameter due to insufficient input sanitization and output escaping. All versions up to and including 5.4.12 are affected, and updating to the latest version is recommended.
Azərbaycanca: WordPress üçün Advanced File Manager plaginində saxlanılan XSS zəifliyi aşkarlanıb. 'soundFile' parametrindəki kifayət qədər input sanitization və output escaping olmaması səbəbindən, 5.4.12 versiyasına qədər olan bütün versiyalar təsirlənir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15009?
This vulnerability affects the Advanced File Manager plugin.
How can I protect my site from CVE-2026-15009?
It is recommended to update the Advanced File Manager plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.