CVE-2026-15249: Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link
The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15249?
The severity of CVE-2026-15249 is rated as risk 36, indicating a significant potential impact.
How do I fix CVE-2026-15249?
To fix CVE-2026-15249, update the Patterns Kit WordPress plugin to version 1.0.4 or higher where the vulnerability is addressed.
Who is affected by CVE-2026-15249?
CVE-2026-15249 affects users with Contributor roles and higher who can store malicious payloads through the Patterns Kit plugin.
What type of vulnerability is CVE-2026-15249?
CVE-2026-15249 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
What can an attacker do with CVE-2026-15249?
An attacker can exploit CVE-2026-15249 to execute arbitrary JavaScript in the browser of users who interact with affected content.