CVE-2026-11371: Unknown Betterdocs
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.
Affected products
- Unknown Betterdocs: from 4.0.0, before 4.5.5 (fixed in 4.5.5)
Published 2026-07-16. Last modified 2026-07-16.