PT-2026-63592 · WordPress · Lpagery

·

CVE-2026-15404

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lpagery versions prior to 2.5.8
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping in the lpagery add filter text template post() function. The function is hooked to admin footer and echoes the raw post title of a post referenced by the lpagery template query parameter directly inside a JavaScript single-quoted string literal without proper encoding. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts that execute when a higher-privileged user, such as an administrator, accesses an admin page using the lpagery template parameter pointing to the attacker's post.
Recommendations Update to a version newer than 2.5.7.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15404

Affected Products

Lpagery