What is CVE-2026-15780?
CVE-2026-15780 is a Stored XSS vulnerability in the 'WP Statistics' WordPress plugin via the 'utm_campaign' parameter due to insufficient input sanitization and output escaping. It affects versions up to and including 14.16.8, and users should update the plugin immediately.
Azərbaycanca: CVE-2026-15780, 'WP Statistics' WordPress plaginində 'utm_campaign' parametri vasitəsilə Stored XSS zəifliyidir. 14.16.8 və daha əvvəlki versiyalar təsirlənir; istifadəçilər plaqini dərhal yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15780?
The CVE-2026-15780 vulnerability affects the 'WP Statistics' WordPress plugin.
What should users do to protect against CVE-2026-15780?
Users should update the 'WP Statistics' plugin immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.