This issue affects Prague: from n/a through 2.2.8.
Project Subscriptions
No advisories yet.
Solution
Update the WordPress Prague Plugin to the latest available version (at least 2.2.9).
Workaround
No workaround given by the vendor.
Wed, 03 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fox-themes
Fox-themes prague Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fox-themes
Fox-themes prague Wordpress Wordpress wordpress |
Wed, 03 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8. | |
| Title | WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-03T12:40:13.270Z
Reserved: 2026-06-03T08:54:38.977Z
Link: CVE-2025-15654
Updated: 2026-06-03T12:40:08.941Z
Status : Received
Published: 2026-06-03T09:16:12.863
Modified: 2026-06-03T09:16:12.863
Link: CVE-2025-15654
No data.
OpenCVE Enrichment
Updated: 2026-06-03T14:00:18Z