Sceawere
Vulnerability Detail
CVE-2026-103305UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Stored XSS in Prenotazioni
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Prenotazioni
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Prenotazioni WordPress plugin through 1.7.5 does not have authorisation and CSRF checks when saving its settings, and does not escape some of them when outputting them, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:21.007Z",
"pubdate": "2026-10-11T07:17:21.007Z",
"executiveSummary": "The Prenotazioni WordPress plugin, in versions through 1.7.5, contains critical security flaws involving improper authorization and Cross-Site Scripting (XSS) vulnerabilities. The plugin fails to implement necessary nonces for Cross-Site Request Forgery (CSRF) protection and lacks authorization checks when saving administrative settings. Consequently, unauthenticated attackers can inject arbitrary malicious scripts into the plugin's configuration.\nThis vulnerability leads to Stored XSS, where injected payloads are executed in the browsers of administrators or site visitors. The risk implication is significant, as the impact includes potential session hijacking, unauthorized administrative actions, and redirection of site traffic. Exploitation does not require prior authentication, making the attack surface publicly accessible to any remote threat actor capable of interacting with the vulnerable endpoint. Given the nature of WordPress plugins, such vulnerabilities often lead to full site compromise if administrative sessions are successfully hijacked.",
"technicalDetails": "The vulnerability resides in the settings saving mechanism of the Prenotazioni plugin. The core issue is twofold: the absence of CSRF protection (nonces) and the lack of authorization controls on the backend handler responsible for updating plugin configurations. By design, the plugin fails to verify the request origin or the privileges of the requester, allowing an unauthenticated external entity to submit HTTP POST requests to the settings update function.\nThe exploitation flow initiates when an attacker crafts a malicious HTTP POST request targeting the plugin's settings endpoint. Because the code fails to validate the current user's identity or capabilities (e.g., using current_user_can('manage_options')), the request is processed by the server regardless of the sender's authentication status. The attacker includes arbitrary JavaScript payloads within the input parameters intended for plugin settings. These inputs are subsequently saved to the database without appropriate input sanitization or output escaping.\nOnce the malicious script is persisted in the database, it triggers the Stored XSS condition. When an administrator accesses the settings page or when a public visitor loads a page where these settings are reflected, the browser interprets the stored input as legitimate code rather than data. The browser executes the injected JavaScript within the security context of the victim's session.\nFor administrative victims, this allows the execution of unauthorized actions, such as changing site configurations, modifying user roles, or exfiltrating sensitive cookies. For public visitors, the payload could be used to perform phishing attacks or distribute malware. The vulnerability is confirmed in all versions up to and including 1.7.5, demonstrating a failure in secure coding practices, specifically regarding input validation and output encoding, as well as the reliance on insecure WordPress API usage."
}