What is CVE-2026-15421?
CVE-2026-15421 is a Stored Cross-Site Scripting vulnerability in the Speed Optimizer plugin for WordPress up to version 7.8.0. It allows authenticated users to inject malicious scripts via image tag attributes due to insufficient input sanitization. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15421, WordPress üçün Speed Optimizer plagininin 7.8.0 və əvvəlki versiyalarında aşkarlanan Stored XSS zəifliyidir. Bu, autentifikasiya olunmuş istifadəçilərə şəkil teqləri vasitəsilə zərərli skript yerləşdirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-15421 require authentication?
Yes, this Stored XSS vulnerability can be exploited by authenticated users.
What action is recommended to mitigate CVE-2026-15421?
It is recommended to update the Speed Optimizer plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.