A vulnerability has been found in mahethekiller Header Footer Script Adder Plugin up to 2.1 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation of the argument asm_code causes cross site scripting.

This vulnerability is registered as CVE-2026-15394. Remote exploitation of the attack is possible. No exploit is available.