Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Unauthenticated Reflected Cross-Site Scripting via 'new_kb_config' Parameter
- ID
- WPSEC-2026-0504
- Plugin
- Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (echo-knowledge-base)
- Affected
- from 14.0.0 before 17.311.0
- Remediation
- Update to 17.311.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search on WPSec AttackSurface
- Fix released
- Published
Description
The Echo Knowledge Base plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_kb_config' parameter in versions 14.0.0 up to, and including, 17.214.0. This is due to the Frontend Editor page-reload preview applying the JSON-decoded 'new_kb_config' request value, which is also accepted from the query string, to the KB configuration without nonce verification or sanitization, and outputting those values unescaped in the page's inline CSS. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into clicking a link. In versions 15.220.0 and later the preview is applied only for logged-in users with Frontend Editor access (Editors and Administrators by default); earlier versions apply it for any visitor.
References
- https://wpsec.com/vuln/WPSEC-2026-0504/
- https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/
- https://wordpress.org/plugins/echo-knowledge-base/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS