CVE-2025-15690
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 09, 2026
Vendor
unknown
Description
The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page. The Content Mask WordPress plugin before 1.8.5.6's option to restrict its use by role does not prevent this.