CVE-2026-28187: WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Knowledge Base for Documentation, FAQs with AI Assistance pluginto a version that resolves this vulnerability.Fixed in 17.212.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28187?
The severity of CVE-2026-28187 is rated as high with a score of 7.1.
How do I fix CVE-2026-28187?
To fix CVE-2026-28187, update the WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin to version 17.211.1 or higher.
What type of vulnerability is CVE-2026-28187?
CVE-2026-28187 is a Cross Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-28187?
CVE-2026-28187 affects all unpatched installations of the Knowledge Base for Documentation, FAQs with AI Assistance plugin version 17.211.0 or lower.
Is authentication required to exploit CVE-2026-28187?
No, exploitation of CVE-2026-28187 can be done without authentication, making it particularly critical.