What is CVE-2026-15032?
CVE-2026-15032 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Comments" WordPress plugin before version 7.6.60, caused by improper escaping of user-supplied URLs in HTML attributes. It allows unauthenticated attackers to inject payloads that execute in the browsers of any user, including administrators, viewing the affected content. Updating the plugin to version 7.6.60 or newer is recommended.
Azərbaycanca: CVE-2026-15032 "Comments" WordPress plaginində (7.6.60-dən əvvəlki versiyalarda) aşkar edilmiş, autentifikasiya olunmamış istifadəçilərə HTML atributunda URL vasitəsilə Stored XSS hücumu həyata keçirməyə imkan verən zəiflikdir. Bu, administratorlar daxil olmaqla istənilən ziyarətçinin brauzerində skriptin icrasına səbəb ola bilər. Plagini ən azı 7.6.60 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15032?
The vulnerability affects the "Comments" plugin.
To what version should the plugin be updated to prevent CVE-2026-15032?
The plugin should be updated to at least version 7.6.60.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.