{
 "id": "WPSEC-2026-0504",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0504/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0504/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0504/index.md",
 "title": "Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Unauthenticated Reflected Cross-Site Scripting via 'new_kb_config' Parameter",
 "description": "The Echo Knowledge Base plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_kb_config' parameter in versions 14.0.0 up to, and including, 17.214.0. This is due to the Frontend Editor page-reload preview applying the JSON-decoded 'new_kb_config' request value, which is also accepted from the query string, to the KB configuration without nonce verification or sanitization, and outputting those values unescaped in the page's inline CSS. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into clicking a link. In versions 15.220.0 and later the preview is applied only for logged-in users with Frontend Editor access (Editors and Administrators by default); earlier versions apply it for any visitor.",
 "plugin": {
  "slug": "echo-knowledge-base",
  "name": "Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search",
  "full_name": "Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search",
  "wordpress_org": "https://wordpress.org/plugins/echo-knowledge-base/",
  "advisories_url": "https://wpsec.com/vuln/plugin/echo-knowledge-base/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/echo-knowledge-base"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "14.0.0",
    "from_inclusive": true,
    "to": "17.311.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 14.0.0 before 17.311.0"
  ]
 },
 "introduced_in": "14.0.0",
 "fixed_in": "17.311.0",
 "remediation": "Update to 17.311.0 or later.",
 "fix_released": "2026-10-04T17:23:04+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-07T10:53:24.242100+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0504/",
  "https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/",
  "https://wordpress.org/plugins/echo-knowledge-base/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/echo-knowledge-base",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}