Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-08-10
CVE-2026-15047 - Before 260805 Does Not Escape Several Shortcode Attributes Plugin
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
PLUGIN
Before 260805 Does Not Escape Several Shortcode Attributes
CVE-2026-15047
Risk Score
