Sceawere

Vulnerability Detail

CVE-2026-103478UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Premium Packages

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
codename065
Product
Premium Packages – Sell Digital Products Securely
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkout[billing][phone] (and state / taxid / email)' parameter in all versions up to, and including, 7.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T08:17:03.793Z",
  "pubdate": "2026-10-10T08:17:03.793Z",
  "executiveSummary": "The Premium Packages – Sell Digital Products Securely plugin for WordPress contains a critical Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 7.2.6.\nThis vulnerability stems from inadequate input sanitization and output escaping mechanisms applied to specific checkout parameters.\nThe flaw allows authenticated users with subscriber-level privileges or higher to inject and persist arbitrary malicious JavaScript payloads within the plugin's data handling flow.\nWhen these injected pages are accessed by other users—specifically administrators or high-privilege users viewing order details—the scripts execute within their browser context.\nThe risk implications include unauthorized administrative actions, session hijacking, credential theft, and potential full site compromise.\nExploitation requires the attacker to possess at least a subscriber-level account, making the threat particularly severe in environments allowing open registration or compromised low-level accounts.",
  "technicalDetails": "The vulnerability resides in the improper handling of user-supplied data within the plugin's checkout processing logic. Specifically, the parameters 'checkout[billing][phone]', 'checkout[billing][state]', 'checkout[billing][taxid]', and 'checkout[billing][email]' fail to undergo rigorous sanitization before being stored in the WordPress database.\nBecause the input is treated as trusted content, an attacker can submit crafted payloads containing malicious HTML tags or JavaScript URI schemes (e.g., <script>alert(document.cookie)</script>) during the checkout submission process.\nThe root cause is a failure to implement context-aware output encoding. When an administrator or authorized user accesses the order management dashboard to review transaction data, the stored malicious payloads are rendered directly into the Document Object Model (DOM) of the admin's browser session without proper escaping.\nThe attack flow begins with an authenticated attacker submitting a checkout request containing the XSS payload in one of the vulnerable billing fields. Upon successful submission, the plugin commits this input to the database. Subsequently, when the target user navigates to the specific order review page, the WordPress environment pulls the unsanitized data and injects it into the administrative panel's response body.\nUpon rendering, the browser interprets the script tag, leading to the execution of arbitrary JavaScript. This execution occurs within the context of the victim's session, granting the attacker the ability to perform actions on behalf of the victim, such as modifying configuration settings, creating new administrative users, or exfiltrating sensitive session tokens.\nGiven that administrative interfaces often involve high-level permissions, the impact is severe, effectively bypassing the security boundary that should separate a low-privileged subscriber from the site administrator's environment. The vulnerability persists until the specific malicious record is manually deleted from the database or the underlying code is corrected to sanitize input upon receipt and escape output upon rendering."
}
CVE-2026-103478: Stored XSS in Premium Packages (MEDIUM Severity, CVSS: 6.4) | Sceawere