What is CVE-2026-15404?
CVE-2026-15404 is a Stored Cross-Site Scripting (XSS) vulnerability in the Lpagery plugin for WordPress, affecting versions up to 2.5.7. It occurs due to insufficient input sanitization and output escaping in the 'lpagery_add_filter_text_template_post()' function, which is executed in the admin footer. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15404, WordPress-in Lpagery plaginində post başlıqları vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyidir. Bu, 2.5.7 versiyasına qədər təsir edir və admin panelində işlədilən funksiyanın zəif sanitizasiyasına görə yaranır. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WordPress Lpagery plugin are affected by CVE-2026-15404?
This Stored XSS vulnerability affects versions of the Lpagery plugin up to 2.5.7.
What is the root cause of the CVE-2026-15404 vulnerability?
The vulnerability is caused by insufficient input sanitization and output escaping in the 'lpagery_add_filter_text_template_post()' function, which is executed in the admin footer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.