Junglewise Threat Intelligence

CVE-2026-6813: Continually WordPress plugin stored XSS in admin settings

CVE-2026-6813 · Severity: medium · CVSS 4.4 · Published 2026-05-12

Executive brief

The Continually plugin for WordPress, which is used to integrate lead generation and chatbot services, contains a security flaw in its administrative settings. This vulnerability allows an authorized administrator to save malicious scripts that will run when other users visit the site. This issue primarily impacts WordPress multi-site environments or specific configurations where standard security restrictions on HTML content have been disabled.

Technical details

The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the administrative settings. An authenticated attacker with administrator-level permissions can inject arbitrary web scripts into the database. These scripts then execute in the browser of any user accessing the affected pages. This vulnerability specifically impacts WordPress multi-site installations and environments where the 'unfiltered_html' capability has been disabled for administrators. The flaw exists in versions up to and including 4.3.1.

Affected products

  • Continually Continually Up to, and including, 4.3.1

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References