Sceawere
Vulnerability Detail
CVE-2026-107657UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HivePress Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- hivepress
- Product
- HivePress – Business Directory, Listings & Classified Ads Plugin
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have configured a text-type custom user attribute whose display format places %value% inside an HTML attribute context (e.g., the documented pattern <a href="%value%">Custom link</a>), and for front-end user profiles to be enabled — both of which reflect the plugin's standard, documented configuration.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T09:16:38.940Z",
"pubdate": "2026-10-10T09:16:38.940Z",
"executiveSummary": "The HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability stems from inadequate input sanitization and insufficient output escaping within custom user attribute fields.\nThe flaw allows unauthenticated attackers to inject malicious JavaScript payloads that execute within the context of a victim's browser when accessing affected pages.\nThe vulnerability affects all plugin versions up to and including 1.7.31.\nExploitation requires that an administrator has configured a custom user attribute using a text-type field where the display format incorporates the %value% placeholder within an HTML attribute context.\nSuccessful exploitation enables attackers to perform unauthorized actions on behalf of authenticated users, potentially leading to session hijacking, unauthorized data access, or the redirection of users to malicious websites.\nThe risk profile is significant given the ease of triggering script execution through standard front-end user profile interactions.",
"technicalDetails": "The vulnerability is a classic Stored Cross-Site Scripting (XSS) flaw occurring due to improper handling of user-supplied data in custom user attribute fields. The plugin fails to sanitize input at the entry point and, more critically, fails to perform context-aware output encoding when rendering data on the front end.\nThe exploitation surface is defined by the plugin's 'custom user attribute' feature. When an administrator defines an attribute with a display format that embeds the %value% placeholder directly into an HTML attribute—for example, <a href=\"%value%\">Custom link</a>—the plugin performs a direct string substitution.\nBecause the plugin does not escape the malicious input provided to the attribute field, an attacker can supply a payload designed to break out of the HTML attribute context. For instance, providing a value such as 'javascript:alert(document.domain)' or breaking the attribute using '\" onmouseover=\"alert(1)' allows for the arbitrary execution of JavaScript.\nThe attack flow follows these steps: 1. An attacker identifies a target site running HivePress where front-end user profiles are enabled and a custom attribute is exposed in an HTML attribute context. 2. The attacker submits a crafted payload into the custom user attribute field. 3. The plugin saves this malicious string into the database without adequate sanitization. 4. When a user (e.g., an administrator or another visitor) views the profile page containing this attribute, the plugin renders the stored payload directly into the HTML output. 5. The victim's browser parses the injected script, leading to immediate execution in the victim's session.\nThe vulnerability requires no authentication for the submission of malicious data if the profile fields are public-facing, yet it facilitates the compromise of higher-privileged accounts if those users view the infected profile pages. The persistence of the payload in the database ensures that every visitor accessing the affected profile page triggers the malicious script, magnifying the potential impact significantly."
}