What is CVE-2026-15646?
CVE-2026-15646 is a Stored XSS vulnerability in the Brands for WooCommerce WordPress plugin (versions ≤ 3.8.8) via the 'style' Shortcode Attribute due to insufficient input sanitization and output escaping. This flaw allows authenticated users with Contributor-level access to inject malicious scripts. Updating the plugin to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-15646, WordPress-in Brands for WooCommerce plaginində (3.8.8-ə qədər versiyalarda) 'style' Shortcode Atributu vasitəsilə mövcud olan Stored XSS zəifliyidir. Bu zəiflik autentifikasiya olunmuş, Contributor səviyyəli istifadəçilərə zərərli skript yerləşdirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-15646 and what privilege level is required for the attack?
This vulnerability affects the Brands for WooCommerce WordPress plugin. An authenticated user with Contributor-level access is required for the attack.
What measure should be taken to protect against CVE-2026-15646?
It is recommended to update the Brands for WooCommerce plugin to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.