Sceawere

Vulnerability Detail

CVE-2026-39724UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in HTTP Requests Manager

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
veppa
Product
HTTP Requests Manager
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:44.533Z",
  "pubdate": "2026-10-06T09:17:44.533Z",
  "executiveSummary": "The HTTP Requests Manager plugin for WordPress, in all versions up to and including 1.3.11, is susceptible to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability arises due to insufficient sanitization and output encoding of user-supplied input provided to the application, allowing an attacker to inject arbitrary malicious scripts into the web pages viewed by other users.\nThe flaw is categorized as a high-severity security issue because it requires no authentication to execute, significantly lowering the barrier for exploitation.\nImpact includes the potential for session hijacking, unauthorized actions performed on behalf of an authenticated user, credential theft, and the redirection of users to malicious third-party domains.\nSuccessful exploitation allows an attacker to execute JavaScript in the victim's browser context, bypassing standard security controls if the victim has administrative or elevated privileges.\nThe risk is particularly acute given that the vulnerability can be triggered via a crafted URL sent to an unsuspecting user, making it ideal for phishing and social engineering campaigns.",
  "technicalDetails": "The vulnerability originates from the improper handling of HTTP parameters within the HTTP Requests Manager component. The affected component fails to perform adequate input validation or context-aware output encoding on parameters passed through the request handling logic.\nSpecifically, the plugin processes user-supplied data and reflects it back into the Document Object Model (DOM) of the generated HTML response without verifying the integrity or nature of the content. This facilitates the injection of arbitrary HTML or JavaScript tags.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload embedded within a vulnerable query parameter. When a victim, particularly an administrator, visits this crafted URL, the server reflects the malicious script back to the user's browser.\nSince the script is served from a trusted domain, the victim's browser executes the payload within the security context of the affected site. This allows the script to bypass Same-Origin Policy (SOP) restrictions.\nAs the vulnerability is unauthenticated, the exploitation does not require the attacker to have an active session or specific privileges on the target WordPress instance. The attack is fully network-exposed, meaning any external user can trigger the vulnerability if the target instance is reachable.\nPost-exploitation, the malicious script can perform a variety of operations, including, but not limited to, stealing session cookies to achieve account takeover, intercepting keystrokes, capturing sensitive administrative data, or forcing the victim's browser to perform unintended actions such as modifying plugin configurations, creating new administrator accounts, or exfiltrating private user content through background AJAX requests.\nBecause the payload is reflected, the exploitation remains temporary unless persistent hooks are established via subsequent administrative actions initiated by the malicious script itself. The lack of robust Content Security Policy (CSP) headers or input sanitization routines in the affected versions 1.3.11 and below is the primary root cause facilitating this injection vector."
}
CVE-2026-39724: Unauthenticated XSS in HTTP Requests Manager (HIGH Severity, CVSS: 7.1) | Sceawere