What is CVE-2026-15047?
CVE-2026-15047: The s2Member WordPress plugin (before version 260805) fails to properly escape several shortcode attributes, allowing Contributor-level users to inject arbitrary JavaScript via stored XSS when a post is viewed. Update the plugin to the latest version to mitigate the issue.
Azərbaycanca: CVE-2026-15047: s2Member WordPress plaqinində (260805 versiyasından əvvəl) bəzi shortcode atributlarının düzgün escapelanmaması nəticəsində Contributor səviyyəli istifadəçilər posta injected JavaScript yerləşdirə bilər. Bu, stored XSS zəifliyinə gətirib çıxarır. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What user level can exploit the CVE-2026-15047 vulnerability in the s2Member plugin?
This stored XSS vulnerability can be exploited by Contributor-level users.
To which version should the s2Member plugin be updated to mitigate CVE-2026-15047?
The plugin is vulnerable in versions before 260805, so updating to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.