Stored Cross-Site Scripting in WP Docs for WordPress
CVE-2026-3878
6.4MEDIUM
What is CVE-2026-3878?
The WP Docs plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping. This flaw allows authenticated users with subscriber-level access or higher to inject malicious web scripts through the 'wpdocs_options[icon_size]' parameter. The injected scripts can compromise the security of users visiting affected pages, executing unwanted actions and potentially leading to data breaches.
Affected Version(s)
WP Docs 0 <= 2.2.9