# Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Unauthenticated Reflected Cross-Site Scripting via 'new_kb_config' Parameter

- **ID:** WPSEC-2026-0504
- **Plugin:** Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (`echo-knowledge-base`), https://wordpress.org/plugins/echo-knowledge-base/
- **Affected versions:** from 14.0.0 before 17.311.0
- **Fixed in:** 17.311.0 (Update to 17.311.0 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/echo-knowledge-base
- **Fix released:** 2026-10-04
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0504/

## Description

The Echo Knowledge Base plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_kb_config' parameter in versions 14.0.0 up to, and including, 17.214.0. This is due to the Frontend Editor page-reload preview applying the JSON-decoded 'new_kb_config' request value, which is also accepted from the query string, to the KB configuration without nonce verification or sanitization, and outputting those values unescaped in the page's inline CSS. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into clicking a link. In versions 15.220.0 and later the preview is applied only for logged-in users with Frontend Editor access (Editors and Administrators by default); earlier versions apply it for any visitor.

## References

- https://wpsec.com/vuln/WPSEC-2026-0504/
- https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/
- https://wordpress.org/plugins/echo-knowledge-base/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0504/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
