Medium severity6.1NVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
CVE-2026-11371
CVE-2026-11371
Description
The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.