Junglewise Threat Intelligence

CVE-2026-11898: videousermanuals White Label CMS Stored XSS in admin settings

CVE-2026-11898 · Severity: medium · CVSS 4.4 · Published 2026-07-11

Executive brief

White Label CMS, a WordPress plugin used to customize the dashboard and branding for clients, contains a security flaw in its administrative settings. An attacker with administrator-level access could inject malicious scripts into the website's management interface. This could lead to unauthorized actions being performed in the browser of other site administrators, though it primarily impacts multi-site environments or specific hardened configurations.

Technical details

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the Admin_Dashboard.php and Settings.php components. Authenticated attackers with administrator-level permissions can inject arbitrary web scripts into admin settings. These scripts execute when a user accesses the affected pages. The vulnerability specifically impacts WordPress multi-site installations and environments where the 'unfiltered_html' capability has been disabled for administrators. The issue is present in all versions up to and including 2.7.12.

Affected products

  • videousermanuals White Label CMS up to, and including, 2.7.12

Timeline

  • 2026-07-11: advisory: NVD publication date

References