Stored Cross-Site Scripting Vulnerability in Toocheke Companion Plugin for WordPress
CVE-2026-15604
6.4MEDIUM
What is CVE-2026-15604?
The Toocheke Companion plugin for WordPress allows authenticated attackers with contributor-level access and above to exploit a stored cross-site scripting vulnerability. This occurs due to inadequate input sanitization in the 'series_bg_color' post meta field, enabling raw POST values to be stored unsanitized. Moreover, the plugin fails to properly escape output in the admin dashboard's series list table, where stored values are directly injected into style attributes. This can lead to arbitrary web script execution when an administrator views the affected pages.
Affected Version(s)
Toocheke Companion 0 <= 2.10