Junglewise Threat Intelligence

CVE-2026-15298: WordPress TelSender DOM-Based XSS in Telegram API responses

CVE-2026-15298 · Severity: high · CVSS 7.2 · Published 2026-07-10

Executive brief

The TelSender plugin for WordPress, which connects website forms to Telegram bots, contains a security flaw that allows attackers to inject malicious code through Telegram chat titles. If an administrator interacts with the plugin's settings page, this code can execute in their browser, potentially allowing the attacker to perform unauthorized actions or steal sensitive session information. This affects all versions of the plugin up to and including 1.14.14.

Technical details

The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting (XSS) due to insufficient input sanitization when processing Telegram API responses. Specifically, the plugin fails to properly sanitize attacker-controlled chat titles retrieved via the API. An unauthenticated attacker can set a malicious Telegram chat title which is then processed by the plugin's AJAX handlers and view templates. The malicious script executes in the context of an administrator's browser session when they visit the TelSender settings page and click the 'Tested' button. This vulnerability is present in versions up to and including 1.14.14.

Affected products

  • pechenki TelSender <= 1.14.14

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References