PT-2026-60412 · WordPress · Betterdocs
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BetterDocs versions prior to 4.5.5
Description
Insufficient sanitization of AI-generated documentation summaries and improper output escaping allow unauthenticated users to perform prompt injection. This enables the storage of malicious payloads that execute in the browser of any visitor viewing the affected page, including administrators. This issue results in Stored Cross-Site Scripting (XSS), a technique where a malicious script is permanently stored on the target server.
Recommendations
Update the plugin to version 4.5.5 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Betterdocs