PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15644 codesupplyco CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.333Z and has not been modified since then. The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' Shortcode Attribute in all versions up to, and including, 3.1.0. This is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Users of the Powerkit plugin for WordPress should verify the version in use and restrict contributor-level access. Additional input sanitization and output escaping for the 'style' shortcode attribute are recommended.

Vendor
codesupplyco
Product
Powerkit – Supercharge your WordPress Site
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

Users of the Powerkit plugin for WordPress, particularly those with contributor-level access or above, should be aware of this vulnerability and take steps to mitigate it. This includes verifying the version of the Powerkit plugin in use, restricting contributor-level access, and implementing additional input sanitization and output escaping for the 'style' shortcode attribute. Security teams and vulnerability management teams should also review the vulnerability and plan for remediation.

Technical summary

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' Shortcode Attribute in all versions up to, and including, 3.1.0. This is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM.

Defensive priority

Authenticated attackers with contributor-level access could inject web scripts via the 'style' shortcode attribute in the Powerkit plugin.

Recommended defensive actions

  • Inventory and verify the version of the Powerkit plugin in use
  • Restrict contributor-level access and above to prevent authenticated attackers from injecting web scripts
  • Implement additional input sanitization and output escaping for the 'style' shortcode attribute
  • Monitor for suspicious activity and update the plugin to a patched version when available
  • Perform a thorough review of the affected plugin and its usage in your environment
  • Consider implementing compensating controls for exposed systems while remediation is scheduled
  • Review and update asset inventory to ensure accurate tracking of affected systems

Evidence notes

The CVE-2026-15644 record indicates that the Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' Shortcode Attribute. The vulnerability exists in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This information is based on the CVE record and NVD detail. Further verification is recommended to confirm affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.333Z and has not been modified since then.