AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-15298

HIGH · CVSS 7.2 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The TelSender plugin for WordPress is susceptible to DOM-Based Cross-Site Scripting due to inadequate input sanitization of Telegram API responses, affecting all versions up to 1.14.14. This vulnerability allows unauthenticated attackers to inject malicious scripts through manipulated chat titles, which can be executed when an administrator interacts with the plugin's settings. WordPress site administrators using the TelSender plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-15298
Severity
HIGH
CVSS
7.2
EPSS
0.31%
WordPress

Original NVD Description

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input sanitization when processing Telegram API responses containing attacker-controlled chat titles. This makes it possible for unauthenticated attackers to inject malicious scripts via Telegram chat titles that execute when an administrator opens the TelSender settings page and clicks the "Tested" button.