CVE-2026-1263Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.0 due to insufficient input sanitization, insufficient output escaping, and missing capabilities checks in the 'webling_admin_save_form' and 'webling_admin_save_memberlist' functions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject Webling forms and memberlists with arbitrary web scripts that will execute whenever an administrator views the related form or memberlist area of the WordPress admin.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-10); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-19: 1Technical Details · 2026-04-10: 104-1004-1104-19
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-111
General1
2026-04-191
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-1263-webling-version-3-9-0-medium-vulnerability-proof-of-concept CVE-2026-1263 #WordPress plugin #vulnerability webling #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE‑2026‑1263 targeting the Webling WordPress plugin is linked, indicating that the vulnerability has been demonstrated publicly.

    0000064
    6 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-1263 📊 Severity: 6.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1263 #CVE-2026-1263 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/oKfF2aBVa7

    Post summary

    The tweet merely announces a new CVE with severity and affected product details, lacking deeper technical or exploit information.

    0000055
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1263 The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.0 due to insufficient input sanitization, insuff… https://www.cve.org/CVERecord?id=CVE-2026-1263

    Post summary

    An announcement identifies a stored XSS flaw in Webling WordPress plugin (v3.9.0 and earlier) caused by inadequate input sanitization, with no PoC, exploit, patch, or active exploitation details provided.

    00000128
    57.0K followersView on X

Explore more