CVE-2026-15649: Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15649?
CVE-2026-15649 has a medium severity rating of 6.4.
How do I fix CVE-2026-15649?
To fix CVE-2026-15649, update the Powerkit WordPress plugin to the latest version beyond 3.1.0.
Who is affected by CVE-2026-15649?
Authenticated users with Contributor+ roles using Powerkit versions up to 3.1.0 are affected by CVE-2026-15649.
What type of vulnerability is CVE-2026-15649?
CVE-2026-15649 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can an unprivileged user exploit CVE-2026-15649?
No, CVE-2026-15649 can only be exploited by authenticated users with Contributor+ permissions.