Stored Cross-Site Scripting in Powerkit Plugin for WordPress
CVE-2026-15644
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15644?
The Powerkit plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, stemming from inadequate input sanitization and output escaping mechanisms. This allows authenticated attackers with contributor-level access or higher to insert malicious scripts into the 'style' shortcode attribute. When a user accesses a manipulated page, these scripts execute, potentially compromising user data and site integrity. All versions up to and including 3.1.0 are affected, emphasizing the need for prompt updates and security reviews.
Affected Version(s)
Powerkit β Supercharge your WordPress Site 0 <= 3.1.0