Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-11371 - BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection

CVE ID :CVE-2026-11371 Published : July 16, 2026, 6 a. m. | 58 minutes ago Description :The BetterDocs WordPress plugin before 4.

5. 5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators. Severity: 0.

Originally reported by CVE Recent
0 comments

0 comments

Posting as FierceHawk659
0/1000

No comments yet. Be the first to start the discussion.