Sceawere
Vulnerability Detail
CVE-2026-104814UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Form Block Unauthenticated XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- epiphyt
- Product
- Form Block
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:39.973Z",
"pubdate": "2026-10-06T09:17:39.973Z",
"executiveSummary": "The Form Block plugin for WordPress is susceptible to an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in versions 1.8.1 and below.\nThis vulnerability arises due to insufficient input sanitization and output encoding within the form submission processing mechanism.\nThe flaw allows an unauthenticated remote attacker to inject malicious JavaScript payloads into the web application via form fields.\nWhen a privileged user, such as an administrator, views the submitted data within the WordPress dashboard, the malicious script executes within the context of their active session.\nThe primary risk implications involve the potential for session hijacking, unauthorized administrative actions, sensitive data exfiltration, or the deployment of persistent malicious content on the affected site.\nExploitation requires no authentication and relies on the victim interacting with the compromised dashboard interface after a malicious submission is made.\nThis vulnerability poses a significant security risk, as it permits attackers to bypass standard access controls by leveraging the trust associated with authenticated administrator sessions.",
"technicalDetails": "The vulnerability exists within the Form Block plugin's data processing logic, specifically where user-supplied input from form submissions is stored and subsequently rendered in the administrative backend.\nThe root cause is identified as the failure to sanitize user inputs effectively before storage and the failure to escape output correctly when displaying these inputs in the WordPress administration area.\nThe attack flow commences with an unauthenticated user submitting a web form containing a crafted XSS payload embedded within one of the input fields. The plugin accepts this input and persists it directly into the database without applying appropriate filtering or neutralization of HTML tags and JavaScript event handlers.\nSubsequently, an authorized user (typically an administrator) accesses the plugin's submission management or notification interface to review the received entries. As the application renders the stored input, the browser interprets the malicious script injected into the database field.\nBecause the execution context is the WordPress administrative interface, the payload executes with the privileges of the authenticated user. This environment provides the attacker with a high-value target for performing unauthorized actions, such as modifying configuration settings, creating new administrative accounts, or redirecting site traffic.\nThe impact is magnified because the execution occurs within the victim's browser session, allowing the script to bypass Same-Origin Policy (SOP) restrictions related to the site's domain. The payload can be designed to steal session cookies, capture form data, or perform background requests (CSRF) against the WordPress REST API or administrative endpoints without the user's explicit consent.\nAffected versions are identified as <= 1.8.1. Given that no authentication is required to submit the form, the attack vector is exposed to any network-connected user capable of reaching the submission endpoint. Successful exploitation does not necessitate specialized knowledge of the site structure, as the vulnerability is inherent to the plugin's default input handling mechanism.\nPost-exploitation, an attacker can maintain persistence or escalate privileges by weaponizing the administrator's account to execute further malicious code or inject content into site pages, effectively compromising the integrity and confidentiality of the entire WordPress installation."
}