CyberRota Yorumu
Detaylı analiz gerekiyor.
CVE
CVE-2026-15931
Severity
UNKNOWN
CVSS
N/A
EPSS
Yok
WordPress Java
Orijinal NVD Açıklaması
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.