Stored Cross-Site Scripting in FastBots Plugin for WordPress
CVE-2026-6800

4.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-6800?

The FastBots plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability, allowing authenticated users with administrator-level permissions to inject malicious web scripts. This vulnerability arises from inadequate input sanitization and output escaping in the admin settings interface, affecting all versions up to and including 1.0.12. This flaw specifically impacts installations where 'unfiltered_html' is disabled and only in multi-site environments, creating a security risk whenever a user visits an affected page.

Affected Version(s)

FastBots 0 <= 1.0.12

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto
.