PatchSiren cyber security CVE debrief
CVE-2026-15644 codesupplyco CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.333Z and has not been modified since then. The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' Shortcode Attribute in all versions up to, and including, 3.1.0. This is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Users of the Powerkit plugin for WordPress should verify the version in use and restrict contributor-level access. Additional input sanitization and output escaping for the 'style' shortcode attribute are recommended.
- Vendor
- codesupplyco
- Product
- Powerkit – Supercharge your WordPress Site
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
Users of the Powerkit plugin for WordPress, particularly those with contributor-level access or above, should be aware of this vulnerability and take steps to mitigate it. This includes verifying the version of the Powerkit plugin in use, restricting contributor-level access, and implementing additional input sanitization and output escaping for the 'style' shortcode attribute. Security teams and vulnerability management teams should also review the vulnerability and plan for remediation.
Technical summary
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' Shortcode Attribute in all versions up to, and including, 3.1.0. This is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM.
Defensive priority
Authenticated attackers with contributor-level access could inject web scripts via the 'style' shortcode attribute in the Powerkit plugin.
Recommended defensive actions
- Inventory and verify the version of the Powerkit plugin in use
- Restrict contributor-level access and above to prevent authenticated attackers from injecting web scripts
- Implement additional input sanitization and output escaping for the 'style' shortcode attribute
- Monitor for suspicious activity and update the plugin to a patched version when available
- Perform a thorough review of the affected plugin and its usage in your environment
- Consider implementing compensating controls for exposed systems while remediation is scheduled
- Review and update asset inventory to ensure accurate tracking of affected systems
Evidence notes
The CVE-2026-15644 record indicates that the Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' Shortcode Attribute. The vulnerability exists in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This information is based on the CVE record and NVD detail. Further verification is recommended to confirm affected scope and severity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.333Z and has not been modified since then.