Sceawere

Vulnerability Detail

CVE-2026-39726UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in Lumise Product Designer

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
Lumise NEO
Product
Lumise Product Designer
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:44.833Z",
  "pubdate": "2026-10-06T09:17:44.833Z",
  "executiveSummary": "Lumise Product Designer versions 2.1.1 and earlier are susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw enables remote, unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThe vulnerability arises from improper neutralization of user-supplied input before rendering it in the application's interface. Because the vulnerability does not require authentication, it poses a significant risk to site administrators and end-users.\nSuccessful exploitation allows an attacker to perform actions on behalf of the victim, such as hijacking session cookies, capturing sensitive authentication tokens, modifying web page content, or redirecting users to malicious external domains. This compromises the integrity and confidentiality of the web application and its users.\nGiven the nature of XSS, the impact is highly dependent on the privileges of the victim; however, in a Content Management System (CMS) context, this frequently leads to full administrative account takeover. There are no specific complex exploitation requirements, as the vulnerability is accessible over standard network interfaces through the web application's frontend.",
  "technicalDetails": "The vulnerability is identified as a Stored or Reflected XSS flaw resulting from the failure of the Lumise Product Designer plugin to perform adequate input sanitization and output encoding on user-controllable parameters. Specifically, the application processes incoming HTTP requests and reflects the data back into the DOM without verifying the character set or stripping malicious script tags.\nThe root cause lies in the insufficient server-side validation of input fields that are subsequently rendered via the product designer's frontend interfaces. By submitting a crafted HTTP request containing malicious script payloads (e.g., <script>alert(document.cookie)</script>), an attacker can force the application to treat these payloads as executable code rather than plain text data.\nThe attack flow typically initiates when an unauthenticated attacker transmits a crafted GET or POST request to the vulnerable endpoint within the Lumise plugin. Because the application lacks robust filtering mechanisms, the payload is stored or processed by the server and ultimately embedded into the HTML response delivered to the client-side browser.\nUpon receipt of the malicious response, the victim's browser interprets the injected JavaScript. Since the script executes within the security context of the origin (the vulnerable website), it inherits full permissions to access the Document Object Model (DOM), browser storage (localStorage, sessionStorage), and active session cookies. This grants the attacker the ability to bypass Same-Origin Policy (SOP) protections specific to the vulnerable site.\nTechnical consequences of this vulnerability include, but are not limited to, session hijacking, defacement of the design interface, and the potential for exfiltrating sensitive design metadata or customer data processed by the Lumise plugin. As there is no requirement for high-privilege access, this vulnerability is considered highly exploitable by external threat actors attempting to compromise the integrity of the WordPress environment where the plugin is hosted.\nAffected versions include all iterations of Lumise Product Designer up to and including 2.1.1. The lack of proper Content Security Policy (CSP) headers or input validation layers within the affected PHP modules makes the application inherently vulnerable to common cross-site scripting injection techniques."
}
CVE-2026-39726: Unauthenticated XSS in Lumise Product Designer (HIGH Severity, CVSS: 7.1) | Sceawere