What is CVE-2026-15016?
The Paid Memberships Pro plugin for WordPress (up to 3.8.1) is vulnerable to Stored XSS via the Readonly User Field in the [pmpro_member_profile_edit] shortcode. This allows attackers to inject malicious scripts. Updating to the latest version is recommended.
Azərbaycanca: WordPress-in "Paid Memberships Pro" plaqini (3.8.1 və daha əvvəl) [pmpro_member_profile_edit] şortkodu vasitəsilə Readonly User Field-də saxlanılan XSS zəifliyinə malikdir. Bu, zərərli skriptlərin sayta yerləşdirilməsinə imkan verə bilər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Paid Memberships Pro plugin are affected by CVE-2026-15016?
Versions 3.8.1 and earlier of the Paid Memberships Pro plugin for WordPress are affected by this vulnerability.
How can CVE-2026-15016 be exploited?
The vulnerability can be exploited via Stored XSS through the Readonly User Field in the [pmpro_member_profile_edit] shortcode, allowing attackers to inject malicious scripts into the site.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.