What is CVE-2026-15393?
CVE-2026-15393 is a stored XSS vulnerability in the Cozy Blocks plugin for WordPress. It allows malicious scripts to be embedded via the 'postMeta.font.size' block attribute due to insufficient sanitization. Users are advised to update the plugin immediately.
Azərbaycanca: CVE-2026-15393, WordPress üçün Cozy Blocks plaginində aşkarlanmış Saxlanılan XSS zəifliyidir. Bu boşluq 'postMeta.font.size' blok atributu vasitəsilə xüsusi skriptlərin yerləşdirilməsinə imkan verir. Plagindən istifadə edən sayt sahibləri dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which plugin was CVE-2026-15393 discovered, and what is its attack vector?
This vulnerability is a stored XSS flaw found in the Cozy Blocks plugin for WordPress. An attacker can embed malicious scripts via the 'postMeta.font.size' block attribute.
What action should Cozy Blocks users take to mitigate CVE-2026-15393?
Site owners using the plugin are advised to update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.