Sceawere

Vulnerability Detail

CVE-2026-39722UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in WPLMS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
VibeThemes
Product
WPLMS
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:44.380Z",
  "pubdate": "2026-10-06T09:17:44.380Z",
  "executiveSummary": "This vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw identified in WPLMS versions 4.972 and below.\nThe vulnerability allows unauthenticated remote attackers to inject arbitrary malicious JavaScript into web pages viewed by other users, including site administrators.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of authenticated users, theft of sensitive session cookies, and persistent redirection to malicious domains.\nBecause the vulnerability is unauthenticated, it does not require any prior access to the system, making it highly accessible for exploitation by remote threat actors.\nSuccessful exploitation compromises the integrity and confidentiality of the WPLMS environment, posing a critical risk to site security and user data privacy.\nOrganizations using affected versions of WPLMS are at significant risk of targeted attacks, necessitating immediate attention to security patching or mitigation strategies.",
  "technicalDetails": "The vulnerability exists due to insufficient sanitization and validation of user-supplied input before it is rendered back to the browser within the context of the WPLMS application.\nThe core issue involves the application's failure to adequately neutralize dangerous characters (such as <, >, \", ') and script tags within input fields, which are subsequently processed and stored or reflected in the Document Object Model (DOM).\nAs an unauthenticated vulnerability, the exploit is initiated by sending a crafted HTTP request containing malicious payload strings to the vulnerable endpoint. Because the application processes this input without requiring a valid session, the attack vector is exposed to the public internet.\nWhen a victim, particularly an administrator with high-level privileges, accesses the page where the injected malicious payload is reflected, the browser interprets the input as executable code rather than plain text. This leads to the execution of arbitrary JavaScript within the security context of the victim's session.\nThe attack flow proceeds as follows: 1. The attacker identifies the vulnerable input vector within WPLMS. 2. The attacker crafts a payload designed to execute a specific JavaScript function or script. 3. The attacker submits the payload via an HTTP GET or POST request to the vulnerable component. 4. The server accepts and improperly stores or reflects this payload. 5. A victim user browses the affected page, triggering the payload in their browser session. 6. The script executes, allowing the attacker to perform actions such as exfiltrating sensitive data, stealing authentication tokens, or forcing the victim to perform unintended operations via Cross-Site Request Forgery (CSRF).\nThe vulnerability is persistent if the malicious script is stored in the database or reflected if it is part of a URL-based input that is echoed back in the server response. In both scenarios, the lack of contextual output encoding is the primary root cause. This flaw allows for the full bypass of client-side security policies, as the script runs under the origin of the WPLMS installation."
}
CVE-2026-39722: Unauthenticated XSS in WPLMS (HIGH Severity, CVSS: 7.1) | Sceawere