CyberRota
← Ana sayfaya dön

CVE-2026-15383

UNKNOWN · CVSS N/A

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-08-03T07:16:40.200 · Çekilme zamanı: 2026-08-03T12:07:32.799454+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-15383
Severity
UNKNOWN
CVSS
N/A
EPSS
Yok
WordPress

Orijinal NVD Açıklaması

The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.