AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15249

MEDIUM · CVSS 5.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Patterns Kit WordPress plugin, up to version 1.0.3, is vulnerable due to inadequate escaping of link attributes, enabling users with Contributor roles to inject malicious scripts that execute in the browsers of visitors who interact with the affected elements. This vulnerability poses a significant risk of cross-site scripting (XSS) attacks, potentially compromising user data and site integrity. WordPress site administrators, particularly those using the Patterns Kit plugin, should prioritize immediate updates to mitigate this risk.

CVE
CVE-2026-15249
Severity
MEDIUM
CVSS
5.4
EPSS
0.16%
WordPress

Original NVD Description

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.