Junglewise Threat Intelligence

CVE-2026-1263: Webling WordPress plugin stored XSS in admin functions

CVE-2026-1263 · Severity: medium · CVSS 6.4 · Published 2026-04-10

Executive brief

The Webling plugin for WordPress, which is used to manage forms and member lists, contains a security flaw that allows users with low-level account access to inject malicious scripts into the website's administrative dashboard. If an administrator views the affected forms or member lists, these scripts could execute, potentially leading to unauthorized actions or the compromise of the administrator's session. This vulnerability poses a risk to the integrity of the website management interface and the security of administrative accounts.

Technical details

The Webling plugin for WordPress (versions up to 3.9.0) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization, output escaping, and missing capability checks in the 'webling_admin_save_form' and 'webling_admin_save_memberlist' functions. An authenticated attacker with Subscriber-level permissions or higher can exploit these flaws to inject arbitrary web scripts into Webling forms and member lists. These scripts are stored in the database and execute in the context of an administrator's browser session when they navigate to the relevant form or member list management areas in the WordPress dashboard. The vulnerability was addressed in version 3.9.1.

Affected products

  • Webling Webling Up to and including 3.9.0

Timeline

  • 2026-04-09: disclosed: Reported by Wordfence
  • 2026-04-10: advisory: NVD publication date
  • 2026-04-24: patched: Last modified date indicating patch availability in version 3.9.1

References