AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15032

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Comments plugin for WordPress versions prior to 7.6.60 is vulnerable due to improper escaping of user-supplied URLs, which can lead to Cross-Site Scripting (XSS) attacks. This flaw allows unauthenticated users to inject malicious scripts that execute in the browsers of anyone viewing the affected content, including administrators. WordPress site administrators and users of the Comments plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-15032
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
WordPress

Original NVD Description

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.