PT-2026-60406 · WordPress · Rpb Chessboard

·

CVE-2026-13042

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RPB Chessboard versions prior to 8.1.3
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. Attackers can inject arbitrary web scripts into pages that execute when a user accesses them. This occurs because the plugin's comment text() filter synthesizes attribute-breaking HTML at render time, bypassing WordPress's save-time kses sanitization by using allowed tags and attributes, such as <a> elements with title and href attributes.
Recommendations Update RPB Chessboard to version 8.1.3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13042

Affected Products

Rpb Chessboard