What is CVE-2026-15394?
CVE-2026-15394 is a Stored Cross-Site Scripting (XSS) vulnerability in the 'Header Footer Script Adder' WordPress plugin. It allows authenticated users to inject malicious scripts via the 'asm_code' snippet meta field due to insufficient sanitization. Users should update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-15394, WordPress-in "Header Footer Script Adder" plaginində aşkarlanmış Stored Cross-Site Scripting (XSS) zəifliyidir. Bu boşluq autentifikasiya olunmuş istifadəçilərə 'asm_code' meta sahəsi vasitəsilə zərərli skript yerləşdirməyə imkan verir. Plagini mümkün qədər tez ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15394?
CVE-2026-15394 was discovered in the "Header Footer Script Adder" plugin.
How can an attacker exploit CVE-2026-15394?
Authenticated users can inject malicious scripts via the 'asm_code' snippet meta field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.