Sceawere
Vulnerability Detail
CVE-2026-39722UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in WPLMS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- VibeThemes
- Product
- WPLMS
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:44.380Z",
"pubdate": "2026-10-06T09:17:44.380Z",
"executiveSummary": "This vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw identified in WPLMS versions 4.972 and below.\nThe vulnerability allows unauthenticated remote attackers to inject arbitrary malicious JavaScript into web pages viewed by other users, including site administrators.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of authenticated users, theft of sensitive session cookies, and persistent redirection to malicious domains.\nBecause the vulnerability is unauthenticated, it does not require any prior access to the system, making it highly accessible for exploitation by remote threat actors.\nSuccessful exploitation compromises the integrity and confidentiality of the WPLMS environment, posing a critical risk to site security and user data privacy.\nOrganizations using affected versions of WPLMS are at significant risk of targeted attacks, necessitating immediate attention to security patching or mitigation strategies.",
"technicalDetails": "The vulnerability exists due to insufficient sanitization and validation of user-supplied input before it is rendered back to the browser within the context of the WPLMS application.\nThe core issue involves the application's failure to adequately neutralize dangerous characters (such as <, >, \", ') and script tags within input fields, which are subsequently processed and stored or reflected in the Document Object Model (DOM).\nAs an unauthenticated vulnerability, the exploit is initiated by sending a crafted HTTP request containing malicious payload strings to the vulnerable endpoint. Because the application processes this input without requiring a valid session, the attack vector is exposed to the public internet.\nWhen a victim, particularly an administrator with high-level privileges, accesses the page where the injected malicious payload is reflected, the browser interprets the input as executable code rather than plain text. This leads to the execution of arbitrary JavaScript within the security context of the victim's session.\nThe attack flow proceeds as follows: 1. The attacker identifies the vulnerable input vector within WPLMS. 2. The attacker crafts a payload designed to execute a specific JavaScript function or script. 3. The attacker submits the payload via an HTTP GET or POST request to the vulnerable component. 4. The server accepts and improperly stores or reflects this payload. 5. A victim user browses the affected page, triggering the payload in their browser session. 6. The script executes, allowing the attacker to perform actions such as exfiltrating sensitive data, stealing authentication tokens, or forcing the victim to perform unintended operations via Cross-Site Request Forgery (CSRF).\nThe vulnerability is persistent if the malicious script is stored in the database or reflected if it is part of a URL-based input that is echoed back in the server response. In both scenarios, the lack of contextual output encoding is the primary root cause. This flaw allows for the full bypass of client-side security policies, as the script runs under the origin of the WPLMS installation."
}