Sceawere
Vulnerability Detail
CVE-2026-32572UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP User Frontend Unauthenticated XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- weDevs
- Product
- WP User Frontend Pro
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:42.847Z",
"pubdate": "2026-10-06T09:17:42.847Z",
"executiveSummary": "The WP User Frontend Pro plugin, specifically versions 4.2.13 and earlier, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw stems from insufficient input sanitization and output escaping within the plugin's data processing mechanisms. The vulnerability allows remote, unauthenticated attackers to inject malicious JavaScript payloads into web pages viewed by other users, including administrators.\nSuccessful exploitation of this vulnerability enables a range of malicious activities, including session hijacking, the theft of sensitive authentication cookies, unauthorized actions performed on behalf of legitimate users, and the redirection of users to malicious third-party websites. Because the vulnerability does not require authentication, it poses a high risk to the confidentiality, integrity, and availability of the affected WordPress installation. The vulnerability affects all systems utilizing the WP User Frontend Pro plugin within the specified version range. Organizations should treat this as a critical security concern due to the ease of exploitation and the potential for full account takeover if an administrator is targeted.",
"technicalDetails": "The vulnerability resides within the input handling logic of the WP User Frontend Pro plugin, where user-supplied parameters are processed and subsequently reflected back into the browser without adequate sanitization or output encoding. In versions 4.2.13 and lower, the plugin fails to properly validate or sanitize specific input fields before rendering them in the HTML context.\nThe attack flow begins when an attacker crafts a malicious request containing a payload, such as a <script> tag or an event handler (e.g., onload, onerror) embedded within a parameter that the plugin processes. This request is sent to the WordPress server without the need for prior authentication or elevated privileges. Upon receiving the malicious request, the plugin stores or reflects the unsanitized input into the Document Object Model (DOM) of the rendered page. When an unsuspecting user, such as a site administrator or a logged-in user, visits the affected page, the browser interprets the injected string as executable code rather than plain text.\nBecause the execution occurs within the context of the victim's session, the injected JavaScript operates with the same permissions as the victim. This allows the attacker to access sensitive information, including document cookies (potentially leaking session tokens if the HttpOnly flag is missing), perform actions via AJAX requests to the WordPress backend, or exfiltrate data from the page content. The lack of proper contextual output encoding—where data is not encoded according to its placement (e.g., inside an HTML tag, attribute, or script block)—is the fundamental root cause of this XSS vector.\nThis vulnerability is classified as Reflected or Stored XSS depending on whether the payload is transiently returned in the response or persisted in the database. In both scenarios, the vulnerability is exposed over the network via standard HTTP(S) protocols. The impact is escalated significantly when the victim has high-privilege access, as the attacker can manipulate the WordPress environment, install malicious plugins, or create new administrative users, effectively achieving full system compromise through a client-side attack vector."
}