CVE-2026-15249
Deferred Deferred - Pending Action

Patterns Kit WordPress Plugin DOM XSS via Unescaped Link Attribute

Vulnerability report for CVE-2026-15249, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patterns_kit patterns_kit to 1.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Patterns Kit WordPress plugin (version 1.0.3 or below). It occurs because the plugin does not properly escape a link attribute, allowing users with Contributor-level access or higher to inject malicious scripts. These scripts execute in the browsers of other users who view the affected content and interact with the injected element.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the Patterns Kit plugin version 1.0.3 or below. Check for stored XSS payloads in link attributes by reviewing user-generated content, especially from Contributor-level users. Use security plugins like Wordfence or WPScan to scan for known vulnerabilities in the plugin.

Impact Analysis

An attacker with Contributor access could inject scripts that steal user sessions, redirect to malicious sites, or perform actions on behalf of users. Visitors viewing the compromised content may have their data exposed or their browsers compromised when interacting with the affected element.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR (data protection) and HIPAA (health data privacy) by exposing user data. Organizations using the vulnerable plugin may face compliance violations, fines, or legal consequences if user data is compromised through this XSS flaw.

Mitigation Strategies

Immediately update the Patterns Kit plugin to the latest version if an update is available. If no update exists, consider disabling the plugin until a fix is released. Restrict Contributor-level user permissions to reduce attack surface. Monitor for suspicious activity in user-generated content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15249. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart