Junglewise Threat Intelligence

CVE-2026-15820: Builderall for WordPress stored XSS in Photo Module

CVE-2026-15820 · Severity: medium · CVSS 6.4 · Published 2026-09-10

Executive brief

The Builderall for WordPress plugin, used to build and design website pages, contains a vulnerability in its Photo Module that allows authenticated contributors to inject malicious scripts. When an administrator or other user views an affected page, the injected script runs automatically, potentially compromising their account or stealing sensitive information.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Photo Module's 'attributes' setting, arising from insufficient input sanitization and output escaping. An authenticated attacker with contributor-level access or higher can inject arbitrary JavaScript code that persists in the database. The malicious script executes in the browser of any user who accesses the affected page, potentially enabling session hijacking, credential theft, or further site compromise. The vulnerability affects Builderall for WordPress versions up to and including 3.0.2.

Affected products

  • Builderall Builderall for WordPress up to and including 3.0.2

Timeline

  • 2026-09-10: disclosed

References

Related threats