Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High0
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-08-10

CVE-2026-15047 - Before 260805 Does Not Escape Several Shortcode Attributes Plugin

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).

PLUGIN Before 260805 Does Not Escape Several Shortcode Attributes

CVE-2026-15047

UNKNOWN CVSS 0.0 2026-08-10
Scroll to top