PT-2026-31842 · WordPress · Webling

Kate Kligman

·

Published

2026-04-10

·

Updated

2026-04-11

·

CVE-2026-1263

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webling plugin for WordPress versions prior to 3.9.1
Description The Webling plugin for WordPress is susceptible to Stored Cross-Site Scripting due to insufficient input sanitization, insufficient output escaping, and missing capabilities checks in the webling admin save form and webling admin save memberlist functions. Authenticated attackers with Subscriber-level access or higher can inject arbitrary web scripts into Webling forms and memberlists. These scripts will execute when an administrator views the corresponding form or memberlist area within the WordPress admin interface.
Recommendations Update the Webling plugin to version 3.9.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-1263

Affected Products

Webling