What is CVE-2026-15739?
CVE-2026-15739 is a Stored Cross-Site Scripting (XSS) vulnerability in the Rich Showcase for Google Reviews plugin for WordPress, affecting versions up to and including 6.9.9 via the 'pagination' shortcode attribute. This flaw allows authenticated attackers to inject malicious scripts due to insufficient input sanitization and output escaping. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15739 WordPress üçün Rich Showcase for Google Reviews plaginində, 6.9.9 versiyasına qədər olan versiyalarda "pagination" qısa kod atributu vasitəsilə Stored Cross-Site Scripting (XSS) zəifliyidir. Bu, autentifikasiya olunmuş hücumçulara zərərli skriptlər yerləşdirməyə imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which plugin is affected by CVE-2026-15739 and what is its root cause?
CVE-2026-15739 affects the Rich Showcase for Google Reviews plugin for WordPress, up to and including version 6.9.9. The root cause is insufficient input sanitization and output escaping in the 'pagination' shortcode attribute, leading to Stored Cross-Site Scripting (XSS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.