CVE-2026-12731: weDocs WordPress Plugin Stored XSS Vulnerability (v2.3.0 and earlier)
The weDocs WordPress plugin, used for creating AI-powered knowledge bases and documentation sites, contains a security flaw in how it handles certain block settings. Attackers with contributor-level access or higher can embed malicious scripts into pages through two specific settings (sectionTitleTag and articleTitleTag). These scripts execute whenever anyone views the compromised page, potentially compromising visitor security or stealing sensitive information. The vulnerability affects all versions up to and including 2.3.0.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.4 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-07
NVD description (verbatim)
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12731 is a Stored Cross-Site Scripting (XSS) vulnerability in the weDocs plugin arising from insufficient input sanitization and output escaping of the sectionTitleTag and articleTitleTag block attributes. An authenticated attacker with contributor-level permissions or above can inject malicious JavaScript payloads into these parameters. Because the sanitization and escaping mechanisms are absent or inadequate, the injected script persists in the WordPress database and executes in the browser context of any user accessing the affected page. The attack vector is network-based, requires low complexity, and does not require user interaction from the attacker—only that a legitimate user visit the poisoned page. The impact is scoped to confidentiality and integrity of user sessions and page content.
Business impact
Organizations running weDocs may face compromised documentation environments where user sessions, credentials, or sensitive information embedded in pages can be harvested. For teams using the plugin to host internal documentation, client-facing knowledge bases, or support resources, a breach could undermine trust and expose proprietary information. Remediation requires immediate patching to prevent ongoing exposure, particularly in multi-author environments where contributor accounts are common.
Affected systems
All versions of the weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress up to and including version 2.3.0 are affected. The vulnerability requires the attacker to possess at least contributor-level WordPress user privileges. Organizations using older versions or allowing frequent contributor access are at heightened risk.
Exploitability
Exploitation is straightforward for an authenticated attacker with contributor permissions—no special tools, network manipulation, or user interaction from the target is required. The attacker modifies the sectionTitleTag or articleTitleTag block attributes via the WordPress editor, and the malicious payload executes automatically when the page is viewed. This makes it a practical risk in multi-user WordPress environments where contributors are active. The vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog, but the ease of exploitation means organizations should not rely on its relative obscurity for protection.
Remediation
Update the weDocs plugin to a patched version that properly sanitizes and escapes the sectionTitleTag and articleTitleTag parameters. Verify the patched version against the plugin's official release notes or the WordPress plugin repository. Additionally, audit contributor and author accounts for suspicious activity and review page revision history to identify any injected scripts. Consider temporarily restricting contributor access to non-critical pages until patching is complete.
Patch guidance
Check the official weDocs plugin page in the WordPress plugin repository or the vendor's website for the latest patched version. Apply the update through the WordPress dashboard (Plugins > Installed Plugins > weDocs, then Update if available) or manually via SFTP. Test the update in a staging environment first, especially if the plugin is heavily customized. After patching, verify that sectionTitleTag and articleTitleTag attributes are now properly escaped in the frontend output.
Detection guidance
Review WordPress user access logs for any contributor-level or higher accounts making unusual edits to pages containing weDocs blocks. Examine page revision history for unexpected changes to block attributes, particularly sectionTitleTag and articleTitleTag values that contain HTML or script-like syntax. Monitor for browser console errors or unexpected JavaScript execution on pages using the weDocs plugin. Implement content security policies (CSP) that restrict inline script execution to reduce the impact of stored XSS even if present.
Why prioritize this
Although the CVSS score is moderate (6.4), the vulnerability merits prompt attention because: (1) it requires only authenticated access at contributor level, which is common in collaborative WordPress environments; (2) exploitation requires no active user interaction from the attacker; (3) the impact is persistent (stored XSS) affecting every visitor to a compromised page; (4) the scope is changed, meaning other users and system components can be impacted. Organizations should patch within their standard update cycle, prioritizing if contributors are numerous or external.
Risk score, explained
The CVSS 3.1 score of 6.4 reflects a network-accessible vulnerability requiring low attacker complexity and low privilege (authenticated user). The changed scope (S:C) acknowledges that the XSS affects users beyond the attacker's immediate session. However, the score does not account for the practical prevalence of contributor accounts in WordPress or the certainty of exploitation once a malicious contributor is present. In environments with strict contributor vetting and monitoring, risk is lower; in open collaboration or public-facing editing, risk is materially higher.
Frequently asked questions
Can unauthenticated users exploit this vulnerability?
No. The vulnerability requires at least contributor-level WordPress user privileges. Unauthenticated visitors cannot inject the malicious script, though they will execute it if they view an already-compromised page.
What versions of the weDocs plugin are vulnerable?
All versions up to and including 2.3.0 are affected. Check your installed version in the WordPress admin panel under Plugins > Installed Plugins. Update immediately if you are at or below 2.3.0.
What damage could an attacker do with a stored XSS in our documentation site?
An attacker could steal session cookies, capture keystrokes or form submissions, redirect users to phishing sites, deface content, or insert malware distribution frames. The impact depends on what sensitive data or functionality is exposed through the affected documentation pages.
Do we need to take action if we have strict contributor approval workflows?
Yes. Even with careful vetting, a compromised contributor account or a malicious insider poses immediate risk. Patch promptly and consider reviewing contributor permissions and activity logs as a defense-in-depth measure.
This analysis is provided for informational purposes by SEC.co and does not constitute legal advice or a guarantee of protection. The vulnerability details, CVSS score, and affected versions are based on published advisories current as of the analysis date. Organizations must verify patch availability and compatibility with their specific installations before applying updates. No exploit code or step-by-step weaponization guidance is provided. Always test patches in a non-production environment first. SEC.co makes no warranty regarding the completeness or accuracy of future patch releases or vendor remediation timelines. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide