{"id":"CVE-2026-85415","title":"The Audio Player Block  WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in…","summary":"The Audio Player Block  WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in…","severity":"none","cwe":["CWE-79"],"product":"Audio Player Block","affected":["audio_player_block >= 1.1.0 < 1.6.3"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:06.203","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85415","references":[{"url":"https://wpscan.com/vulnerability/3ca9c087-311b-4c55-8871-fba318f654b3/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.552Z","slug":"CVE-2026-85415","body":"## Overview\n\nThe Audio Player Block  WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}