What is CVE-2026-15647?
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Brands for WooCommerce WordPress plugin via the 'br_brand_tooltip' Term Meta Field, affecting all versions up to 3.8.8. Authenticated attackers with specific capabilities can exploit insufficient input sanitization and output escaping to inject malicious scripts. Users should update the plugin to the latest patched version immediately.
Azərbaycanca: Brands for WooCommerce WordPress plaqinində 'br_brand_tooltip' Term Meta Field üzərindən Stored Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Bu, 3.8.8-ə qədər bütün versiyalara təsir edir və autentifikasiya olunmuş hücumçulara xüsusi imkanlarla istifadəçi sessiyalarını ələ keçirməyə şərait yaradır. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
What method is used to exploit the CVE-2026-15647 vulnerability in the Brands for WooCommerce plugin?
The vulnerability is exploited via the 'br_brand_tooltip' Term Meta Field due to insufficient input sanitization and output escaping, allowing a Stored XSS attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.