Sceawere
Vulnerability Detail
CVE-2026-12980UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Post Snippets Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Post Snippets
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-11T07:17:23.890Z",
"pubdate": "2026-10-11T07:17:23.890Z",
"executiveSummary": "The Post Snippets WordPress plugin, version 4.2.4 and earlier, contains a stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output escaping.\nThe vulnerability allows authenticated users with at least Contributor-level privileges to inject malicious JavaScript payloads into snippets.\nWhen these snippets are subsequently rendered or viewed by other users, including high-privileged administrators, the injected scripts execute within the context of the victim's session.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the WordPress installation, potentially facilitating session hijacking, unauthorized administrative actions, or defacement.\nExploitation requires the attacker to hold an authenticated account with the minimum capability of 'Contributor' or higher. No complex network interception is required, as the payload is persistent and stored directly within the plugin's data structure.",
"technicalDetails": "The core of this vulnerability lies in the insufficient server-side validation and output-side sanitization of user-supplied variables within the Post Snippets plugin's snippet substitution engine.\nWhen a user creates or modifies a snippet, the plugin allows for the inclusion of variable placeholders. The vulnerable code path fails to implement adequate escaping mechanisms when these variables are processed for display during the rendering phase.\nBecause the plugin does not properly sanitize these inputs against malicious HTML or JavaScript tags before rendering them in the frontend or backend interface, the application becomes susceptible to Stored XSS.\nThe attack flow begins with an authenticated contributor crafting a snippet containing a malicious payload designed to execute within the victim's browser, such as an external script include or a document.cookie exfiltration script.\nUpon saving this snippet, the malicious payload is stored in the WordPress database. When a user with sufficient permissions visits a page or post where the specific snippet is rendered, the WordPress site dynamically inserts the stored payload into the DOM.\nBecause the application fails to perform context-aware output escaping (e.g., failing to neutralize characters such as '<', '>', '\"', and \"'\"), the browser interprets the injected payload as executable code rather than plain text.\nThis execution occurs under the security context of the victim's current session. Consequently, if an administrator views the page containing the malicious snippet, the attacker can execute arbitrary administrative functions—such as creating new administrative accounts, modifying plugin settings, or exfiltrating sensitive session tokens—without the victim's knowledge or consent.\nThis behavior persists across all locations where the vulnerable snippets are utilized, effectively turning a low-privilege Contributor account into a vector for full site compromise or cross-site request forgery (CSRF) chains.\nThe failure to adhere to secure coding standards, specifically regarding the separation of data and code during output rendering, is the definitive root cause of the flaw within the affected versions up to 4.2.4."
}