CVE detail
CVE-2026-11898
The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 11
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)Wordfence
.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13039 Patch Status Patched Published Jul 9, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Niv Kochan More Details > Flatsome FundEngine – Donation
vendorwww.wordfence.comJul 16, 2026, 8:29 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/1f12cdb6-df2d-419d-a29c-1ff7f9d098f4?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3600959%40white-label-cms&new=3600959%40white-label-cmsplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Settings.php#L228plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Settings.php#L124plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Admin_Dashboard.php#L465plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.9/includes/classes/Admin_Dashboard.php#L430plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Settings.php#L228plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Settings.php#L124plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Admin_Dashboard.php#L465plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/white-label-cms/tags/2.7.12/includes/classes/Admin_Dashboard.php#L430plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 11, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14856CVSS 6.3 · Medium
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization…
- CVE-2026-65764CVSS 5.1 · Medium
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
- CVE-2026-15928CVSS 8.2 · High
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
- CVE-2026-17496CVSS 8.1 · High
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without…
- CVE-2026-15425CVSS 6.4 · Medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up…
- CVE-2026-57531CVSS 5.1 · Medium
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScrip…