Medium severity5.4NVD Advisory· Published Aug 12, 2026· Updated Aug 26, 2026
CVE-2026-15249
CVE-2026-15249
Description
The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.0.3
Patches
Vulnerability mechanics
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)Wordfence Blog · Aug 21, 2026