Executive brief
BetterDocs is a WordPress plugin used to create and manage documentation and knowledge bases. A security flaw in its AI-powered summarization feature allows unauthorized visitors to inject malicious scripts into documentation pages. If an administrator or another user views these pages, the attacker could potentially take over their session, steal sensitive data, or modify site content.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the BetterDocs plugin for WordPress due to insufficient sanitization of AI-generated content. The AI Doc Summarizer feature is exposed to unauthenticated users, who can use prompt injection techniques to force the AI to generate a malicious JavaScript payload. Because the plugin stores and displays this output without proper encoding or sanitization, the payload executes in the context of any user viewing the documentation page. This can lead to session hijacking or administrative account takeover. Exploitation requires the AI Doc Summarizer feature to be enabled with a valid API key. The issue is fixed in version 4.5.5.
Affected products
- WPDeveloper BetterDocs < 4.5.5
Timeline
- 2026-06-25: disclosed
- 2026-07-16: advisory: NVD publication date
- 2026-07-16: patched: Fixed in version 4.5.5