What is CVE-2026-15245?
CVE-2026-15245 is an improper escaping vulnerability in the BNE Testimonials WordPress plugin, where a shortcode attribute is not sanitized for a JavaScript context before being echoed into an inline script. This allows users with Contributor role or higher to inject arbitrary JavaScript that executes in other users' browsers. Updating to version 2.0.8.2 or later is required to fix the issue.
Azərbaycanca: CVE-2026-15245 BNE Testimonials WordPress plaginində qısa kod atributunun JavaScript konteksti üçün düzgün qaçırılmaması ilə bağlıdır. Bu zəiflik Contributor roluna malik istifadəçilərə ixtiyari JavaScript inyeksiya etməyə imkan verir. Plaginin 2.0.8.2 versiyasından əvvəlki versiyaları təsirlənir, ona görə də dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15245?
CVE-2026-15245 affects the BNE Testimonials plugin.
Which version of the BNE Testimonials plugin fixes CVE-2026-15245?
Updating to version 2.0.8.2 or later is required to fix the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.