PT-2026-31842 · WordPress · Webling
Kate Kligman
·
Published
2026-04-10
·
Updated
2026-04-11
·
CVE-2026-1263
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webling plugin for WordPress versions prior to 3.9.1
Description
The Webling plugin for WordPress is susceptible to Stored Cross-Site Scripting due to insufficient input sanitization, insufficient output escaping, and missing capabilities checks in the
webling admin save form and webling admin save memberlist functions. Authenticated attackers with Subscriber-level access or higher can inject arbitrary web scripts into Webling forms and memberlists. These scripts will execute when an administrator views the corresponding form or memberlist area within the WordPress admin interface.Recommendations
Update the Webling plugin to version 3.9.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webling