CVE-2026-15245: BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15245?
CVE-2026-15245 has a risk score of 36.
How do I fix CVE-2026-15245?
To fix CVE-2026-15245, upgrade the BNE Testimonials plugin to version 2.0.8.2 or above.
Who is affected by CVE-2026-15245?
Users with the contributor role and above in the BNE Testimonials plugin are affected by CVE-2026-15245.
What type of vulnerability is CVE-2026-15245?
CVE-2026-15245 is classified as a stored cross-site scripting (XSS) vulnerability.
How can CVE-2026-15245 be exploited?
CVE-2026-15245 can be exploited by injecting arbitrary JavaScript via the slider shortcode, affecting users viewing the page.