Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-6858 is a stored cross-site scripting vulnerability in the Transbank Webpay WordPress plugin (versions before 1.14.0) that allows unauthenticated attackers to inject malicious scripts into plugin log entries. When an administrator views those logs, the script executes in their browser, enabling session hijacking, credential theft, or full administrative account takeover. Organizations running this plugin on customer-facing WordPress sites face risk of unauthorized site modification, payment flow tampering, and reputational damage.

Author

Tech Jacks Solutions