cleantalk
Vulnerabilities and Security Researches

Transbank Webpay REST, CVE-2026-6858

CVE, Research URL

CVE-2026-6858

Application

Transbank Webpay REST

Published on
Jun 22, 2026
Research Description
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
Affected versions
max 1.14.0.
Status
vulnerable