Sceawere

Vulnerability Detail

CVE-2026-104396UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Name Directory Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
Jeroen Peters
Product
Name Directory
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory allows Stored XSS.This issue affects Name Directory: from n/a through 1.34.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:07.793Z",
  "pubdate": "2026-10-05T09:17:07.793Z",
  "executiveSummary": "The Name Directory plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input.\nThis vulnerability allows an attacker to inject and persist malicious JavaScript code within the application's database, which is subsequently executed in the browser of any user viewing the affected page, including administrators.\nThe flaw affects all versions of Name Directory from the initial release through version 1.34.2.\nThe impact of this vulnerability is significant, as successful exploitation enables attackers to perform unauthorized actions on behalf of authenticated users, hijack sessions, exfiltrate sensitive data, or modify the content of the affected web pages.\nBecause the payload is stored server-side, this vulnerability constitutes a persistent threat, requiring no interaction from the victim other than navigating to the compromised page.\nThe risk is exacerbated by the potential for privilege escalation if an administrator views the injected payload, allowing the attacker to gain control over the WordPress installation.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the Name Directory plugin to adequately sanitize, validate, or escape input fields before storing them in the WordPress database and rendering them in the front-end interface.\nThe vulnerability falls under the CWE-79 classification: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nIn a Stored XSS attack scenario, the malicious payload is submitted through a vulnerable input field (e.g., name entries, description fields, or configuration parameters) processed by the plugin. Because the plugin lacks sufficient output encoding or input filtering, the malicious script is stored in the database verbatim.\nWhen a user or administrator subsequently visits a page where the plugin retrieves and displays this data, the application embeds the unsanitized malicious JavaScript directly into the HTML context. The victim's browser, interpreting the injected script as legitimate code originating from the trusted domain, executes the payload.\nThe attack flow follows a structured trajectory: 1) The attacker identifies an input vector within the Name Directory plugin that does not enforce strict character filtering or output encoding. 2) The attacker crafts a malicious script payload designed to perform specific actions, such as stealing session cookies (document.cookie), redirecting the user, or executing administrative actions via forged requests. 3) The attacker submits this payload through the vulnerable input field, ensuring it is committed to the database. 4) The victim accesses the web page where the plugin displays the stored, malicious entry. 5) The browser renders the injected script within the application's context, leading to unauthorized execution.\nThe vulnerability is persistent, meaning the payload remains active until it is manually removed from the database or the vulnerable code is patched to correctly handle the output. Successful exploitation does not inherently require high-level privileges if the input vector is accessible to unauthenticated or low-privilege users, though the impact is maximized when targeting administrative sessions.\nPost-exploitation, the attacker can leverage the victim's session to bypass security controls, manipulate site settings, inject additional malicious content, or compromise the underlying server environment depending on the victim's permissions and the server-side configuration."
}
CVE-2026-104396: Name Directory Stored XSS (MEDIUM Severity, CVSS: 6.5) | Sceawere