Junglewise Threat Intelligence

CVE-2026-15404: LPagery WordPress Plugin Stored XSS in post titles

CVE-2026-15404 · Severity: medium · CVSS 6.4 · Published 2026-07-23

Executive brief

LPagery, a WordPress plugin used for bulk page generation, contains a security flaw that allows users with low-level access (like Contributors) to inject malicious scripts into the website's administrative dashboard. These scripts are triggered when a site administrator views specific pages, potentially allowing the attacker to perform unauthorized actions or steal sensitive information. This could lead to a full compromise of the website if an administrator's session is hijacked.

Technical details

The LPagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function. This function, hooked to admin_footer, echoes the raw post_title of a post referenced by the 'lpagery_template' query parameter directly into a JavaScript single-quoted string literal without using esc_js() or esc_html(). Authenticated attackers with Contributor-level permissions can exploit this by creating a post with a malicious title. The script executes when a higher-privileged user, such as an administrator, accesses an admin page with the specific query parameter pointing to the attacker's post ID. A patch is available in versions following 2.5.7.

Affected products

  • niklaslindemann Bulk Page Generator – LPagery up to, and including, 2.5.7

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References