Unrated severityNVD Advisory· Published Sep 30, 2026
CVE-2026-85415
CVE-2026-85415
Description
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.6.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.