← Back to CVE search

CVE-2026-6858

Transbank Webpay

Description

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

CVSS 7.1EPSS 0.293%Risk 0.73
View source
Published
2026-06-22 06:16:21
Affected versions
<1.14.0
Type
Web application
Last modified
2026-07-22 16:18:52
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L