Sceawere
Vulnerability Detail
CVE-2026-102393UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Starter Templates Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- Brainstorm Force
- Product
- Starter Templates
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T09:17:05.850Z",
"pubdate": "2026-10-05T09:17:05.850Z",
"executiveSummary": "The Brainstorm Force Starter Templates (astra-sites) plugin is vulnerable to Stored Cross-Site Scripting (XSS), categorized under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis vulnerability exists within versions 4.7.7 and prior, allowing authenticated attackers with sufficient privileges to inject malicious scripts into the application's database.\nWhen a victim, such as an administrator, views the compromised page or data, the stored payload executes within the context of their browser session.\nThe impact includes potential unauthorized access to session tokens, administrative credentials, or the ability to perform actions on behalf of the victim, such as modifying site configuration or injecting further malicious content.\nExploitation requires the attacker to have an authenticated account with privileges sufficient to submit input processed by the vulnerable plugin.\nGiven that administrative interfaces are frequently targeted, the risk implication is high, as successful exploitation can lead to full site compromise.",
"technicalDetails": "The vulnerability resides in the way the Starter Templates plugin handles and persists user-supplied input. Specifically, the plugin fails to perform adequate output encoding or context-aware sanitization on specific data fields before rendering them in the administrative backend or frontend interfaces.\nIn a Stored XSS scenario, the root cause is the lack of server-side validation and sanitization of input vectors that are subsequently stored in the WordPress database (e.g., in the options table or post meta).\nThe attack flow commences when an authenticated user injects malicious JavaScript into an input field processed by the Starter Templates plugin. The plugin accepts this input without stripping or escaping sensitive characters such as <, >, \", or ' and writes it directly to the database.\nWhen a subsequent request occurs—typically when an administrator views a page generated by the plugin—the application retrieves the malicious string from the database and inserts it directly into the HTML response body without appropriate encoding.\nThe browser, interpreting the injected script as legitimate code from the trusted origin, executes the payload. Because this occurs within the security context of an authenticated administrative session, the attacker can hijack the session, exfiltrate sensitive data such as CSRF tokens or cookies, or execute administrative tasks (e.g., creating a new administrator account) via background HTTP requests.\nThe attack does not require sophisticated network access beyond the ability to authenticate to the WordPress site. The vulnerability affects the plugin's core functionality responsible for rendering templates or configuration data. Because the malicious payload is stored permanently, the attack is persistent, meaning every user or administrator accessing the vulnerable component will trigger the script execution until the database entry is manually cleaned or the vulnerability is patched.\nThe failure follows a classic lack of adherence to secure coding practices, specifically failing to apply the principle of 'filter input, escape output' (FIO). Without rigorous sanitization at the point of ingestion and strict escaping at the point of rendering, the application remains susceptible to persistent code injection."
}