Junglewise Threat Intelligence

CVE-2026-12734: weDevs weDocs Stored XSS in connectorWidth Block Attribute

CVE-2026-12734 · Severity: medium · CVSS 6.4 · Published 2026-07-03

Technologies: weDevs weDocs. Vendors: weDevs.

Executive brief

The weDocs plugin for WordPress, which provides documentation and AI chatbot features, contains a security flaw that allows users with contributor-level access to inject malicious scripts into pages. These scripts execute automatically when other users, including administrators, visit the affected pages. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

The weDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'connectorWidth' block attribute within the Sidebar component. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page. Because the payload is stored in the database, the script executes in the context of any user's browser who views the compromised page. This vulnerability is tracked as CWE-79 and affects all versions up to and including 2.3.0. A patch has been released in subsequent versions to address the improper neutralization of input.

Affected products

  • weDevs weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot up to, and including, 2.3.0

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats