What is CVE-2026-15730?
CVE-2026-15730 is a Stored Cross-Site Scripting (XSS) vulnerability in the GamiPress WordPress plugin up to version 7.9.9.1, exploitable via the 'heading_size' Shortcode Attribute due to insufficient input sanitization. Unauthenticated attackers can inject malicious scripts that execute when users access affected pages, allowing for potential data theft or site defacement. Users should immediately update the plugin to the latest version and consider temporarily restricting the use of the vulnerable shortcode.
Azərbaycanca: CVE-2026-15730, GamiPress WordPress plaginində 'heading_size' Shortcode atributu vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyidir. 7.9.9.1-ə qədər bütün versiyalar təsirlənir, giriş təmizlənməsinin kifayət etməməsi səbəbindən autentifikasiyasız hücumçulara zərərli skript yerləşdirməyə imkan verir. İstifadəçilər dərhal plaqini ən son versiyaya yeniləməli və təhlükə aradan qalxana qədər təsirlənmiş shortcode-dan istifadəni məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-15730?
CVE-2026-15730 affects the GamiPress WordPress plugin.
What can happen as a result of exploiting this vulnerability?
Unauthenticated attackers can inject malicious scripts that execute when users access affected pages, potentially leading to data theft or site defacement.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.