VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-11371

CVE-2026-11371: The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and

Published Jul 16, 2026 CVSS 6.1

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.

Affected AI Products

prompt injection
Get the weekly digest. Every Monday: top AI security stories of the week. Free.