The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. This is due to insufficient input sanitization in the toocheke_series_bg_color_save() function (which stores the raw $_POST value in post meta) and insufficient output escaping in the series admin column rendering (where the stored value is concatenated into a style attribute without esc_attr()). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user, such as an administrator, accesses the series list table in the admin dashboard.
We have discovered 287 live websites that are affected by CVE-2026-15604.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 287 live websites (86% of Toocheke Companion install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 30 versions ( 79% of all versions) |
| 206 websites | |
| 22 websites | |
| 11 websites | |
| 7 websites | |
| 5 websites | |
| 5 websites | |
| 4 websites | |
| 2 websites | |
| 2 websites |
| .com | 248 websites |
| .net | 13 websites |
| .de | 4 websites |
| .org | 4 websites |
| .co | 2 websites |
| .co.uk | 2 websites |
| .ca | 1 websites |
| .es | 1 websites |
| .fi | 1 websites |
| .fr | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ***,*** | ||
| ************.com | ***,*** | ||
| *************.com | ***,*** | ||
| **********.com | ***,*** | ||
| ***.co | *,***,*** | ||
| *********.com | *,***,*** | ||
| *******************.com | *,***,*** | ||
| ********.com | *,***,*** | ||
| ***********.com | *,***,*** | ||
| *******.net | *,***,*** |
FAQ