Sceawere
Vulnerability Detail
CVE-2026-32571UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ohio Extra Subscriber XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 16h ago
- Vendor
- Colabrio
- Product
- Ohio Extra
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T09:17:42.703Z",
"pubdate": "2026-10-06T09:17:42.703Z",
"executiveSummary": "The Ohio Extra WordPress theme, in versions 3.6.8 and below, contains a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper input sanitization and output encoding within the theme's subscriber-facing functionality. By exploiting this vulnerability, an authenticated attacker with subscriber-level access can inject malicious JavaScript payloads into the application.\nWhen a high-privileged user, such as an administrator, views the compromised data within the WordPress dashboard, the injected script executes within their browser session. This allows for unauthorized actions performed on behalf of the administrator, such as creating new rogue accounts, modifying site configurations, or redirecting traffic. Because the vulnerability requires only subscriber-level privileges, it significantly lowers the barrier for exploitation. The risk to the site's integrity and the confidentiality of administrative sessions is substantial. Organizations utilizing affected versions of Ohio Extra should prioritize remediation to prevent potential account takeover and unauthorized site modifications.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the failure of the Ohio Extra theme to sufficiently sanitize user-supplied input before persisting it to the database or rendering it in the administration interface. The flaw resides in input fields accessible to users with the 'subscriber' role, where the theme processes metadata or profile-related settings without adequate validation.\nThe attack flow begins when an authenticated attacker, holding subscriber-level privileges, submits a crafted payload into vulnerable input fields within the theme's settings or profile interface. The application incorrectly assumes this data is safe and stores it in the database. When an administrator later navigates to the affected page in the WordPress backend, the theme retrieves the stored, malicious payload and reflects it into the HTML document object model (DOM) without proper output encoding or context-aware sanitization.\nBecause the payload is executed within the security context of the administrator's active session, the script inherits the administrator's authentication tokens and permissions. The browser interprets the injected JavaScript as legitimate code originating from the trusted domain. This execution allows the attacker to manipulate the Document Object Model, perform arbitrary requests via the Fetch or XMLHttpRequest APIs, or exfiltrate sensitive session cookies if the HttpOnly flag is missing or bypassed through secondary vectors.\nThe affected component is the Ohio Extra theme, specifically targeting versions 3.6.8 and earlier. The vulnerability is exploitable over the network, provided the attacker has valid credentials to log in as a subscriber. No additional complex prerequisites are required, as the stored nature of the XSS ensures the payload is delivered automatically when the administrative user accesses the tainted component. Post-exploitation, an attacker could achieve complete site compromise by escalating their privileges or by performing actions that modify the server-side application logic through the administrative interface."
}