CVE-2026-6858 Details
Description
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
A stored cross-site scripting vulnerability has been identified in the Transbank Webpay WordPress plugin, affecting versions prior to 1.14.0. The issue arises because the plugin fails to properly sanitize and escape logs before displaying them, which allows unauthenticated users to execute XSS attacks that target logged-in administrators.
Users are advised to update the Transbank Webpay WordPress plugin to version 1.14.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 22, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hackedalert.com/research/transbank-webpay-plugin-xss-to-rce/ | CVE | |
| https://wpscan.com/vulnerability/81035d75-81a5-486a-a9fb-b0d1e0befe3c/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Transbank Webpay | < 1.14.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CVE |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |
Volerion