What is CVE-2026-15726?
CVE-2026-15726 is a Stored Cross-Site Scripting (XSS) vulnerability in the Serious Slider plugin for WordPress (up to 1.4.0) via the 'theme' Shortcode attribute. It allows authenticated attackers with contributor-level access to inject malicious scripts. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-15726, WordPress üçün Serious Slider plaginin 1.4.0 və əvvəlki versiyalarında 'theme' Shortcode atributu vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyidir. Bu, contributor səviyyəli autentifikasiya olunmuş hücumçulara zərərli skript yerləşdirməyə imkan yaradır. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which WordPress plugin and through which attribute is CVE-2026-15726 exploited?
This vulnerability is exploited in the Serious Slider plugin via the 'theme' Shortcode attribute.
What level of authentication is required for an attacker to exploit CVE-2026-15726?
The attacker requires authenticated access at the contributor level.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.