Sceawere
Vulnerability Detail
CVE-2026-103520UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HivePress Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- hivepress
- Product
- HivePress – Business Directory, Listings & Classified Ads Plugin
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an administrator has configured a Text attribute whose display format places the %value% token inside an HTML attribute (e.g., title="%value%"), which is a documented HivePress pattern.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T06:16:38.290Z",
"pubdate": "2026-10-10T06:16:38.290Z",
"executiveSummary": "The HivePress plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing in its custom text attribute implementation. This flaw, present in versions up to and including 1.7.31, arises from inadequate input sanitization and output escaping mechanisms. An authenticated attacker with subscriber-level permissions or higher can inject malicious JavaScript payloads into user-defined field names. When these fields are rendered within specific HTML attributes—a documented usage pattern for HivePress—the injected script executes within the context of the victim's browser session. The primary impact includes potential account takeover, session hijacking, or unauthorized administrative actions. This vulnerability is restricted to environments where administrators have explicitly configured a Text attribute using the %value% token within an HTML attribute context, such as a title or data attribute. Given the ability of even low-privileged users to trigger this payload, the vulnerability presents a significant risk to site integrity and user data confidentiality.",
"technicalDetails": "The root cause of this vulnerability is the failure of the HivePress plugin to sanitize user-supplied input for custom text attributes and the subsequent lack of context-aware output escaping when rendering these attributes on the frontend. Specifically, the application handles the %value% token by directly injecting user-provided data into HTML templates without proper encoding for the specific context in which the data is placed.\nThe vulnerability is exploitable when an administrator configures a Text attribute using a display format that places the %value% placeholder directly inside an HTML attribute—for instance, <div title='%value%'>. Because the application does not validate or encode the contents of the 'custom text attribute' field against HTML attribute injection, an attacker can supply a crafted payload to break out of the HTML attribute context.\nThe attack flow proceeds as follows: First, an authenticated attacker with at least subscriber-level access navigates to the profile or listing settings where custom text attributes can be defined. Second, the attacker inputs a malicious payload designed to terminate the intended attribute, such as: ' onmouseover='alert(document.cookie)'. Third, when a user—including administrators—views the rendered page containing this attribute, the injected JavaScript is parsed by the browser.\nBecause the payload is stored persistently in the database, the script executes every time the affected page is loaded. This persistent nature allows for long-term monitoring or exfiltration of sensitive information, such as CSRF tokens or active session cookies. Since the execution occurs within the context of the victim's session, the attacker can perform actions with the same privileges as the victim, potentially leading to privilege escalation if an administrator views the malicious content. The vulnerability is present in all versions up to 1.7.31 and does not require specialized network access beyond the ability to interact with the WordPress interface as a registered user."
}