What is CVE-2026-15648?
The 'Brands for WooCommerce' plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability via the 'width' Shortcode Attribute. Affecting all versions up to 3.8.8, this flaw allows authenticated attackers with contributor-level access to inject arbitrary scripts due to insufficient input sanitization. Users should immediately update the plugin to the latest version.
Azərbaycanca: WordPress üçün 'Brands for WooCommerce' pluginində 'width' shortcode atributu vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. 3.8.8-ə qədər olan bütün versiyaları təsir edir. Contributor səviyyəsində autentifikasiya olunmuş hücumçu bu zəiflikdən istifadə edərək ixtiyari skriptləri daxil edə bilər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: WordPress
FAQ2
Which WordPress plugin is affected by CVE-2026-15648?
This vulnerability affects all versions of the 'Brands for WooCommerce' plugin up to 3.8.8.
What access level does an attacker need to exploit CVE-2026-15648?
An attacker must be authenticated with contributor-level access to exploit this Stored XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.