Sceawere

Vulnerability Detail

CVE-2026-32569UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in WP Media

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
Joomunited
Product
WP Media folder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:42.397Z",
  "pubdate": "2026-10-06T09:17:42.397Z",
  "executiveSummary": "The WP Media folder plugin, specifically in versions 6.2.2 and below, contains a security vulnerability identified as an unauthenticated Cross-Site Scripting (XSS) flaw.\nThis vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into web pages viewed by other users, including administrators.\nThe impact of a successful exploit is significant, as it enables the execution of arbitrary code within the context of the victim's browser session. This can lead to unauthorized actions performed on behalf of the victim, such as modifying plugin configurations, creating new administrative accounts, or exfiltrating sensitive session cookies.\nBecause the vulnerability does not require authentication, the attack surface is open to any internet-based actor capable of interacting with the vulnerable WordPress installation.\nThe risk is categorized as high, as it compromises the integrity of the administrative interface and the security of authenticated user sessions.\nNo specific user interaction, other than viewing a manipulated page, is required for successful exploitation.",
  "technicalDetails": "The vulnerability resides in the improper handling of user-supplied input within the WP Media folder plugin. Specifically, the plugin fails to adequately sanitize or escape data before reflecting it back to the browser in the administrative dashboard or front-end interface.\nThe root cause is a lack of server-side input validation and output encoding on specific parameters processed by the plugin. When an attacker crafts a malicious request containing a carefully constructed JavaScript payload, the plugin incorrectly stores or reflects this payload without neutralization.\nThe attack flow begins when an attacker sends an unauthenticated HTTP request to the target WordPress instance, targeting specific endpoints exposed by the WP Media folder plugin that process user input. By including a script tag or event handler (such as 'onload' or 'onerror') within the vulnerable parameter, the attacker forces the server to store or echo the payload.\nWhen an administrator or authorized user accesses the affected interface, the injected script is executed by their browser. Since the script executes within the security context of the logged-in user, it can perform any action authorized to that user, such as executing arbitrary administrative functions via AJAX requests.\nBecause the payload is reflected, it can be triggered on either the administrative side, potentially leading to a full site takeover, or on the front-end, potentially impacting site visitors. The absence of strict Content Security Policy (CSP) headers or input validation allows the malicious script to bypass browser protections.\nAffected versions include all releases of WP Media folder up to and including version 6.2.2. The lack of authentication requirements means that attackers do not need a valid account, making this a critical vector for automated scanning and exploitation tools. The post-exploitation impact includes persistent compromise if the payload is stored, or session hijacking if the payload is used to capture sensitive cookies."
}
CVE-2026-32569: Unauthenticated XSS in WP Media (HIGH Severity, CVSS: 7.1) | Sceawere