Sceawere
Vulnerability Detail
CVE-2026-39758UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Midtrans-WooCommerce Unauthenticated Reflected XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- Midtrans
- Product
- Midtrans-WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:47.707Z",
"pubdate": "2026-10-06T09:17:47.707Z",
"executiveSummary": "The Midtrans-WooCommerce plugin, specifically versions 2.32.3 and below, contains a critical security vulnerability classified as an unauthenticated Cross-Site Scripting (XSS) flaw.\nThis vulnerability stems from the improper sanitization and validation of user-supplied input before rendering it back to the user within the web application interface.\nAs an unauthenticated attack vector, the vulnerability allows remote, unprivileged actors to inject arbitrary malicious JavaScript into the browser session of unsuspecting users, including administrative personnel.\nSuccessful exploitation poses a severe risk to the confidentiality, integrity, and availability of the affected WordPress site.\nPotential impacts include the unauthorized exfiltration of sensitive session cookies, administrative account takeover via credential theft, unauthorized actions performed on behalf of the victim, and the potential redirection of users to malicious third-party infrastructure.\nGiven that the attack does not require prior authentication or elevated privileges, the risk profile is significantly elevated for all instances running affected plugin versions.",
"technicalDetails": "The vulnerability resides within the request handling logic of the Midtrans-WooCommerce plugin, where URL parameters or form inputs are processed and subsequently reflected in the HTTP response without appropriate escaping or content security filtering.\nAt its core, the issue is an Input Validation and Output Encoding failure. When the application receives a specially crafted HTTP GET or POST request, it incorporates the attacker-controlled input directly into the DOM (Document Object Model) of the response page.\nThe exploitation flow typically begins with an attacker identifying a non-sanitized input parameter within the plugin's frontend or backend functional endpoints. By injecting a payload containing malicious script tags (e.g., <script>alert(document.cookie)</script>), the attacker forces the victim's browser to parse and execute the code in the context of the vulnerable origin.\nBecause the payload is reflected, the attack can be executed by tricking an authenticated user, such as a shop administrator, into clicking a crafted link containing the malicious payload. Once the victim's browser executes the script, the attacker gains the ability to perform actions permitted by the victim's current session privileges.\nIn a post-exploitation scenario, the attacker can leverage this execution context to access sensitive data, such as authentication tokens or session identifiers, which are then transmitted to an attacker-controlled remote server.\nThe vulnerability affects Midtrans-WooCommerce versions 2.32.3 and earlier. It is categorized as a Reflected XSS vulnerability, requiring the victim to interact with the crafted malicious link to trigger the payload execution. The lack of sufficient server-side input sanitization across relevant plugin functions allows this bypass of security controls, making it possible for attackers to facilitate XSS attacks against the WordPress environment without needing an account on the target system."
}