Sceawere

Vulnerability Detail

CVE-2026-102772UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CMB2 Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
jtsternberg
Product
CMB2
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The front-end save path requires only a CMB2 box nonce, which is emitted to all visitors including unauthenticated guests via a simple GET request, making the attack trivially reachable without any credentials on sites that expose a public CMB2 form writing a textarea_code field.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:00.047Z",
  "pubdate": "2026-10-02T08:17:00.047Z",
  "executiveSummary": "The CMB2 plugin for WordPress (up to and including version 2.13.1) contains a critical Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw arises from inadequate input sanitization and output escaping within the 'textarea_code' field type.\nThe vulnerability allows unauthenticated attackers to inject arbitrary JavaScript, which executes when administrative or other users view the affected content.\nThe attack is exacerbated by the exposure of the CMB2 box nonce to unauthenticated visitors via public GET requests, permitting remote exploitation without prior authentication.\nSuccessful exploitation leads to unauthorized script execution in the context of the victim's session, potentially resulting in account takeover, unauthorized data access, or malicious content injection.",
  "technicalDetails": "The vulnerability resides within the CMB2 framework's handling of specific field types, specifically 'textarea_code' variants (e.g., 'kl_code', 'kl_post_code').\nRoot Cause: The plugin fails to perform rigorous server-side input sanitization or context-aware output escaping when processing these fields. Consequently, malicious payloads containing HTML or JavaScript are stored directly in the database.\nAuthentication and Exposure: The attack surface is highly accessible because the CMB2 box nonce, which is typically required to authorize the submission of form data, is inadvertently leaked to unauthenticated users. By performing a simple GET request to a page containing a public-facing CMB2 form, an attacker can retrieve a valid nonce.\nAttack Flow: 1. An attacker identifies a target site utilizing the CMB2 plugin that exposes a form with a vulnerable 'textarea_code' field. 2. The attacker performs a GET request to the site to harvest the required CMB2 box nonce. 3. The attacker crafts a malicious request containing a payload (e.g., <script>alert(document.cookie)</script>) in the 'textarea_code' parameter. 4. The server accepts the request due to the presence of the legitimate nonce and the lack of server-side sanitization. 5. The malicious script is saved to the database. 6. When a privileged user or administrator visits the page containing the injected content, the browser executes the stored script within the security context of the victim's session.\nPayload Behavior: The injected payload operates within the user's browser, allowing for the manipulation of the Document Object Model (DOM), theft of session cookies, exfiltration of sensitive data, or performative actions on behalf of the user (Cross-Site Request Forgery).\nAffected Versions: All versions up to and including 2.13.1 are susceptible.\nImpact: Because the vulnerability can be triggered via unauthenticated access to public forms, it represents a significant security risk for installations that utilize these specific field types in user-facing entry points."
}
CVE-2026-102772: CMB2 Stored XSS Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere