What is CVE-2026-15100?
The PostX plugin for WordPress up to version 5.0.32 contains a stored XSS vulnerability in the 'searchnoresult' block attribute due to insufficient sanitization. This allows authenticated attackers to inject malicious scripts. Updating the plugin to the latest version is recommended.
Azərbaycanca: WordPress-in PostX plaqini 5.0.32 versiyasına qədər 'searchnoresult' blok atributunda saxlanılan XSS zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş hücumçulara zərərli skript yeritməyə imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15100?
The PostX plugin for WordPress is affected by CVE-2026-15100.
In which block attribute of the PostX plugin is the CVE-2026-15100 vulnerability found?
The CVE-2026-15100 vulnerability is found in the 'searchnoresult' block attribute of the PostX plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.