Stored Cross-Site Scripting Vulnerability in Toocheke Companion Plugin for WordPress
CVE-2026-15604

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2026

What is CVE-2026-15604?

The Toocheke Companion plugin for WordPress allows authenticated attackers with contributor-level access and above to exploit a stored cross-site scripting vulnerability. This occurs due to inadequate input sanitization in the 'series_bg_color' post meta field, enabling raw POST values to be stored unsanitized. Moreover, the plugin fails to properly escape output in the admin dashboard's series list table, where stored values are directly injected into style attributes. This can lead to arbitrary web script execution when an administrator views the affected pages.

Affected Version(s)

Toocheke Companion 0 <= 2.10

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.