CVE-2026-11371: BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11371?
The severity of CVE-2026-11371 is rated at risk 62.
How do I fix CVE-2026-11371?
To fix CVE-2026-11371, update the BetterDocs WordPress plugin to version 4.5.5 or later.
What type of vulnerability is CVE-2026-11371?
CVE-2026-11371 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability.
Who can exploit CVE-2026-11371?
CVE-2026-11371 can be exploited by unauthenticated users who can utilize the AI Doc Summarizer feature.
What are the consequences of CVE-2026-11371?
The consequences of CVE-2026-11371 include the potential for malicious payloads to execute in the browser of users viewing the affected documentation.