VYPR

Platnosci Online Blue Media

by WordPress

CVEs (1)

  • CVE-2026-15002HigAug 16, 2026
    risk 0.47cvss 7.2epss

    The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the…