CVE-2026-15245
Received Received - Intake

BNE Testimonials Plugin DOM XSS via Shortcode Attribute

Vulnerability report for CVE-2026-15245, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: WPScan

Description

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bne_testimonials plugin to 2.0.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the BNE Testimonials WordPress plugin before version 2.0.8.2. It occurs because the plugin does not properly escape a shortcode attribute used in a JavaScript context, allowing users with contributor role or higher to inject malicious JavaScript code that executes when others view the affected content.

Detection Guidance

Check WordPress plugin versions. Use WP-CLI with 'wp plugin list' to see installed versions. Look for BNE Testimonials versions before 2.0.8.2. Inspect pages using affected shortcodes for unexpected JavaScript behavior.

Impact Analysis

Attackers with contributor access or higher can inject malicious scripts into your WordPress site. When visitors view the affected content, the injected scripts run in their browsers, potentially stealing cookies, session tokens, or other sensitive data. This could lead to account takeovers or unauthorized actions on behalf of users.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting user data. If exploited, it may result in unauthorized access to personal or health information, leading to legal penalties, fines, and reputational damage for organizations handling sensitive data.

Mitigation Strategies

Update the BNE Testimonials plugin to version 2.0.8.2 or later immediately. Remove or disable the plugin if an update is not available. Review user roles and restrict contributor-level access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15245. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart