Junglewise Threat Intelligence

CVE-2026-12731: weDevs weDocs Stored XSS in Sidebar Block Attributes

CVE-2026-12731 · Severity: medium · CVSS 6.4 · Published 2026-07-03

Technologies: weDevs weDocs. Vendors: weDevs.

Executive brief

The weDocs plugin for WordPress, which is used to create documentation and knowledge bases, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into pages. When other users, including administrators or site visitors, view these pages, the scripts will execute in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The weDocs WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'sectionTitleTag' and 'articleTitleTag' block attributes within the Sidebar component. An authenticated attacker with at least contributor-level permissions can exploit this by injecting malicious JavaScript into these attributes. Because the plugin fails to properly neutralize this input before it is rendered on the page, the script executes in the context of any user who views the affected documentation page. This vulnerability is present in all versions up to and including 2.3.0. A patch has been released in subsequent versions to address the sanitization failure.

Affected products

  • weDevs weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot up to, and including, 2.3.0

Timeline

  • 2026-07-03: advisory: NVD publication date

References

Related threats