PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15645 codesupplyco CVE debrief

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability's technical impact is heightened because it requires minimal privileges to exploit. Evidence from security researchers at Wordfence indicates that the plugin's insufficient input sanitization and output escaping enable this vulnerability. Defenders should verify the presence of affected versions and plan for updates or mitigations. AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.470Z and has not been modified since then.

Vendor
codesupplyco
Product
Powerkit – Supercharge your WordPress Site
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

Users of the Powerkit plugin for WordPress, particularly those with contributor-level access and above, should be aware of this vulnerability and take necessary precautions. Site administrators and security teams managing WordPress installations with the Powerkit plugin should prioritize updating or mitigating this vulnerability to prevent potential cross-site scripting attacks. Additionally, operators of platforms hosting WordPress sites using the Powerkit plugin should review their exposure and implement compensating controls if necessary.

Technical summary

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability's technical impact is heightened because it requires minimal privileges to exploit.

Defensive priority

Authenticated attackers with contributor-level access could inject web scripts via the 'nav' shortcode attribute in the Powerkit plugin.

Recommended defensive actions

  • Inventory and verify the Powerkit plugin version, checking for updates or patches that address this vulnerability.
  • Restrict contributor-level access and above to prevent authenticated attackers from injecting web scripts.
  • Implement additional security measures, such as Web Application Firewall (WAF) rules, to detect and prevent cross-site scripting attacks.
  • Monitor for suspicious activity and implement incident response plans in case of a security breach.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nav' Shortcode Attribute. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts. Evidence from security researchers at Wordfence indicates that the plugin's insufficient input sanitization and output escaping enable this vulnerability. Defenders should verify the presence of affected versions and plan for updates or mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.470Z and has not been modified since then.