What is CVE-2026-15604?
The Toocheke Companion plugin for WordPress (versions up to 2.10) is vulnerable to Stored Cross-Site Scripting via the 'series_bg_color' post meta field due to insufficient input sanitization in the toocheke_series_bg_color_save() function. Users should update the plugin to the latest patched version or disable it until a fix is applied.
Azərbaycanca: WordPress üçün Toocheke Companion plaginində (2.10 və daha əvvəl versiyalarda) 'series_bg_color' post meta sahəsi vasitəsilə Stored Cross-Site Scripting zəifliyi aşkarlanıb. Bu, toocheke_series_bg_color_save() funksiyasında daxil olunan məlumatın kifayət qədər təmizlənməməsi səbəbindən baş verir. İstifadəçilər plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which function is responsible for the CVE-2026-15604 vulnerability in the Toocheke Companion plugin?
The vulnerability is caused by insufficient input sanitization in the 'toocheke_series_bg_color_save()' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.