CVE 7.1 HIGH

Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS_CVE-2026-6858

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Description

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

Basic Information

ID CVE-2026-6858
Source WPScan
Published Jun 22, 2026 at 06:00
Modified Jun 22, 2026 at 12:55

Affected Product

Vendor Unknown
Product Transbank Webpay
Affected Versions Unknown Transbank Webpay 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.