Sceawere
Vulnerability Detail
CVE-2026-102384UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Author XSS in Supreme Modules
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 3h ago
- Vendor
- Supreme Modules
- Product
- Supreme Modules Lite
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-30T13:17:16.970Z",
"pubdate": "2026-09-30T13:17:16.970Z",
"executiveSummary": "The Supreme Modules Lite plugin, specifically in versions 2.5.63 and below, is susceptible to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability allows authenticated users with contributor-level privileges or higher to inject malicious JavaScript payloads into the WordPress environment through the module's input fields.\nThe security flaw arises from inadequate input sanitization and output encoding when handling user-supplied data within module parameters.\nSuccessful exploitation permits an attacker to execute arbitrary scripts in the context of an administrator's browser session upon viewing the affected content.\nThis could result in full site compromise, unauthorized administrative actions, sensitive data exfiltration, or the redirection of users to malicious external domains.\nThe attack requires the adversary to have an account on the target WordPress installation, specifically one capable of accessing the module creation or editing interface.\nGiven the nature of Stored XSS, the impact is persistent, meaning the malicious payload will execute every time an authorized user views the compromised page or dashboard element.",
"technicalDetails": "The vulnerability manifests as a Stored Cross-Site Scripting (XSS) flaw within the Supreme Modules Lite plugin. The root cause is the failure of the application to properly sanitize and escape input data received through the plugin's interface before persisting it to the database.\nSpecifically, the plugin processes various module configuration parameters without applying adequate input validation. When these parameters are rendered back on either the front-end or within the WordPress administrative dashboard, the lack of proper context-aware output encoding allows for the execution of injected JavaScript.\nThe attack flow begins with a user possessing sufficient privileges (e.g., Contributor or Author) accessing the Supreme Modules configuration panel. The attacker injects a malicious payload, such as '<script>alert(document.cookie)</script>', into one of the input fields supported by the plugin, such as module attributes, text fields, or custom CSS/JS insertion points.\nOnce the module settings are saved, the malicious payload is stored permanently in the database. When a target user—typically an administrator with higher privileges—loads the page containing the malicious module or views the module settings in the dashboard, the browser interprets the stored input as executable script code rather than plain text.\nBecause the malicious script executes within the security context of the victim's session, the attacker inherits the victim's authentication tokens and administrative permissions. This grants the attacker the ability to perform actions on behalf of the victim, such as modifying plugin configurations, injecting further malicious backdoors into themes or files, creating new administrative users, or harvesting sensitive data like CSRF tokens and session identifiers.\nThis vulnerability exists across all versions of Supreme Modules Lite up to and including 2.5.63. The attack is network-exploitable through the application's interface and does not require complex social engineering if the attacker already has legitimate, albeit restricted, access to the module management features. The persistence of the payload ensures that the malicious code executes repeatedly without further interaction from the attacker, maximizing the potential for administrative account takeover."
}