CVE-2026-15249 PUBLISHED

Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link

Assigner: WPScan
Reserved: 09.07.2026 Published: 12.08.2026 Updated: 12.08.2026

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts it into the page, allowing users with a role as low as Contributor to store a payload that executes in the browser of a user who views the content and clicks the affected element.

Product Status

Vendor Unknown
Product Patterns Kit
Versions Default: unknown
  • affected from 0 to 1.0.3 (incl.)

Credits

  • testoun finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE