Executive brief
BetterDocs is a popular WordPress plugin used to create and manage documentation and knowledge base pages. A security flaw allows users with 'Contributor' level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, these scripts could be used to redirect users to malicious sites, steal session information, or deface the website.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the BetterDocs plugin for WordPress due to improper input sanitization and output encoding. An attacker with 'Contributor' or higher privileges can inject arbitrary JavaScript payloads into documentation posts or settings. The vulnerability is triggered when a privileged user (such as an Administrator) or a site visitor views the page containing the malicious script. This is classified as a 'Contributor' level XSS because it requires basic authenticated access to the WordPress dashboard to submit content. The issue is resolved in version 4.7.0.
Affected products
- WPDeveloper BetterDocs <= 4.6.2
Timeline
- 2026-07-14: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-24: advisory: Patchstack advisory published
- 2026-07-27: patched: NVD publication and confirmation of fix in 4.7.0