Sceawere

Vulnerability Detail

CVE-2026-32572UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP User Frontend Unauthenticated XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
weDevs
Product
WP User Frontend Pro
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:42.847Z",
  "pubdate": "2026-10-06T09:17:42.847Z",
  "executiveSummary": "The WP User Frontend Pro plugin, specifically versions 4.2.13 and earlier, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw stems from insufficient input sanitization and output escaping within the plugin's data processing mechanisms. The vulnerability allows remote, unauthenticated attackers to inject malicious JavaScript payloads into web pages viewed by other users, including administrators.\nSuccessful exploitation of this vulnerability enables a range of malicious activities, including session hijacking, the theft of sensitive authentication cookies, unauthorized actions performed on behalf of legitimate users, and the redirection of users to malicious third-party websites. Because the vulnerability does not require authentication, it poses a high risk to the confidentiality, integrity, and availability of the affected WordPress installation. The vulnerability affects all systems utilizing the WP User Frontend Pro plugin within the specified version range. Organizations should treat this as a critical security concern due to the ease of exploitation and the potential for full account takeover if an administrator is targeted.",
  "technicalDetails": "The vulnerability resides within the input handling logic of the WP User Frontend Pro plugin, where user-supplied parameters are processed and subsequently reflected back into the browser without adequate sanitization or output encoding. In versions 4.2.13 and lower, the plugin fails to properly validate or sanitize specific input fields before rendering them in the HTML context.\nThe attack flow begins when an attacker crafts a malicious request containing a payload, such as a <script> tag or an event handler (e.g., onload, onerror) embedded within a parameter that the plugin processes. This request is sent to the WordPress server without the need for prior authentication or elevated privileges. Upon receiving the malicious request, the plugin stores or reflects the unsanitized input into the Document Object Model (DOM) of the rendered page. When an unsuspecting user, such as a site administrator or a logged-in user, visits the affected page, the browser interprets the injected string as executable code rather than plain text.\nBecause the execution occurs within the context of the victim's session, the injected JavaScript operates with the same permissions as the victim. This allows the attacker to access sensitive information, including document cookies (potentially leaking session tokens if the HttpOnly flag is missing), perform actions via AJAX requests to the WordPress backend, or exfiltrate data from the page content. The lack of proper contextual output encoding—where data is not encoded according to its placement (e.g., inside an HTML tag, attribute, or script block)—is the fundamental root cause of this XSS vector.\nThis vulnerability is classified as Reflected or Stored XSS depending on whether the payload is transiently returned in the response or persisted in the database. In both scenarios, the vulnerability is exposed over the network via standard HTTP(S) protocols. The impact is escalated significantly when the victim has high-privilege access, as the attacker can manipulate the WordPress environment, install malicious plugins, or create new administrative users, effectively achieving full system compromise through a client-side attack vector."
}
CVE-2026-32572: WP User Frontend Unauthenticated XSS (HIGH Severity, CVSS: 7.1) | Sceawere