Junglewise Threat Intelligence

CVE-2026-3618: BestWebSoft Columns Stored XSS in print_clmns shortcode

CVE-2026-3618 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

The Columns by BestWebSoft plugin for WordPress, which allows users to add multi-column layouts to posts and pages, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'id' attribute of the [print_clmns] shortcode. While the plugin uses %d to cast the 'id' to an integer for SQL queries, the original unsanitized string is directly embedded into HTML div attributes and inline CSS blocks. An authenticated attacker with Contributor-level access or higher can exploit this to inject arbitrary web scripts. A precondition for successful exploitation is that at least one column must have been previously created by an administrator so that the SQL query returns a result, triggering the vulnerable output branch. All versions up to and including 1.0.3 are affected.

Affected products

  • BestWebSoft (bestweblayout) Columns by BestWebSoft – Additional Columns Plugin for Posts Pages and Widgets up to and including 1.0.3

Timeline

  • 2026-04-08: disclosed: Initial disclosure date
  • 2026-04-08: advisory: Wordfence published advisory

References