SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-11371

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The BetterDocs WordPress plugin prior to version 4.5.5 is vulnerable due to inadequate sanitization of AI-generated documentation summaries, allowing unauthenticated users to inject malicious payloads. This can lead to cross-site scripting (XSS) attacks, impacting any visitor to the affected page, including site administrators. WordPress site owners using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-11371
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
WordPress

Original NVD Description

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.