What is CVE-2026-15794?
The Grid/List View for WooCommerce plugin for WordPress (up to version 3.0.9) is vulnerable to Stored Cross-Site Scripting via the 'position' shortcode attribute. Due to insufficient input sanitization and output escaping, authenticated attackers can inject malicious scripts. Updating the plugin to the latest version is recommended.
Azərbaycanca: WordPress-in Grid/List View for WooCommerce plaqini (3.0.9 və əvvəlki versiyalar) 'position' shortcode atributunda saxlanılan XSS zəifliyinə malikdir. İnsufficient input sanitization və output escaping səbəbindən autentifikasiyalı istifadəçilər zərərli skript yerləşdirə bilərlər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: WooCommerce
FAQ1
Which versions of the Grid/List View for WooCommerce plugin for WordPress are affected by CVE-2026-15794?
Versions up to 3.0.9 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.