Back to overview

CVE-2026-6858

HIGH
7.1
CVSS 3.1
Description
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

Metadata

CVE ID
CVE-2026-6858
State
PUBLISHED
Assigner
WPScan
Reserved
2026-04-22 12:53 UTC
Published
2026-06-22 06:00 UTC
Last updated
2026-06-22 12:55 UTC
Primary CWE
CWE-79
CWE-79 Improper Neutralization of Input During Web Page Gene…
Vendor / Product
Unknown / Transbank Webpay
Sources
cve.org  ·  NVD

Severity & Metrics

7.1 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown Transbank Webpay 0 < 1.14.0
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
CWE-79 adp CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.1 HIGH 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Back to overview