What is CVE-2026-15383?
A vulnerability exists in The Blog Floating Button WordPress plugin up to version 1.4.20, where the visitor User-Agent header is stored via an unauthenticated REST endpoint without sanitization and later rendered unescaped in an admin report page. This allows an unauthenticated attacker to inject malicious code, potentially leading to stored cross-site scripting (XSS) attacks. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: The Blog Floating Button WordPress plagininin 1.4.20-dək versiyalarında zəiflik aşkarlanıb. Doğrulanmamış REST endpoint vasitəsilə ziyarətçinin User-Agent başlığı sanitizə edilmədən saxlanılır və admin hesabat səhifəsində filtirsiz göstərilir ki, bu da autentifikasiya olunmamış hücumçunun zərərli kod yerləşdirməsinə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What type of attack can CVE-2026-15383 lead to in The Blog Floating Button plugin?
It can lead to an unauthenticated stored XSS attack, as the visitor User-Agent header is stored without sanitization and rendered unescaped in the admin report page.
How should The Blog Floating Button plugin be updated to protect against CVE-2026-15383?
The plugin should be immediately updated to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.