CVE-2026-81782: WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 10, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.
Affected Software
1 affected component
WordPress WP Docs<=2.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Docs pluginto a version that resolves this vulnerability.Fixed in 2.3.1
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as subscriber XSS, so an attacker needs subscriber-level access to the affected WordPress site. Exploitation also requires user interaction, according to the UI:R vector.
2
What is the potential impact if exploitation succeeds?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. Successful XSS could affect another security authority or component beyond the vulnerable plugin's immediate scope.