Junglewise Threat Intelligence

CVE-2026-6858: Transbank Webpay WordPress plugin stored XSS in logs

CVE-2026-6858 · Severity: info · CVSS 8.8 · Published 2026-06-22

Executive brief

The Transbank Webpay plugin for WordPress, which facilitates online payments, contains a security flaw in how it handles system logs. An unauthorized attacker can inject malicious scripts into these logs; when a site administrator later views the logs, the script executes in their browser. This could allow an attacker to hijack administrative sessions, modify site settings, or gain full control over the website.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Transbank Webpay Plus REST plugin for WordPress due to insufficient sanitization and escaping of log data before it is rendered in the administrative interface. An unauthenticated remote attacker can trigger the logging of malicious payloads (likely via manipulated request parameters that the plugin records). When an authenticated administrator views the plugin's log page, the stored payload executes in the context of their session. This can lead to session hijacking, unauthorized administrative actions, or complete site compromise. The issue is resolved in version 1.14.0.

Affected products

  • Transbank Transbank Webpay Plus REST < 1.14.0

Timeline

  • 2026-06-01: disclosed: Initial public disclosure by WPScan
  • 2026-06-22: advisory: CVE published to NVD dataset

References