Sceawere

Vulnerability Detail

CVE-2026-39758UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Midtrans-WooCommerce Unauthenticated Reflected XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
Midtrans
Product
Midtrans-WooCommerce
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:47.707Z",
  "pubdate": "2026-10-06T09:17:47.707Z",
  "executiveSummary": "The Midtrans-WooCommerce plugin, specifically versions 2.32.3 and below, contains a critical security vulnerability classified as an unauthenticated Cross-Site Scripting (XSS) flaw.\nThis vulnerability stems from the improper sanitization and validation of user-supplied input before rendering it back to the user within the web application interface.\nAs an unauthenticated attack vector, the vulnerability allows remote, unprivileged actors to inject arbitrary malicious JavaScript into the browser session of unsuspecting users, including administrative personnel.\nSuccessful exploitation poses a severe risk to the confidentiality, integrity, and availability of the affected WordPress site.\nPotential impacts include the unauthorized exfiltration of sensitive session cookies, administrative account takeover via credential theft, unauthorized actions performed on behalf of the victim, and the potential redirection of users to malicious third-party infrastructure.\nGiven that the attack does not require prior authentication or elevated privileges, the risk profile is significantly elevated for all instances running affected plugin versions.",
  "technicalDetails": "The vulnerability resides within the request handling logic of the Midtrans-WooCommerce plugin, where URL parameters or form inputs are processed and subsequently reflected in the HTTP response without appropriate escaping or content security filtering.\nAt its core, the issue is an Input Validation and Output Encoding failure. When the application receives a specially crafted HTTP GET or POST request, it incorporates the attacker-controlled input directly into the DOM (Document Object Model) of the response page.\nThe exploitation flow typically begins with an attacker identifying a non-sanitized input parameter within the plugin's frontend or backend functional endpoints. By injecting a payload containing malicious script tags (e.g., <script>alert(document.cookie)</script>), the attacker forces the victim's browser to parse and execute the code in the context of the vulnerable origin.\nBecause the payload is reflected, the attack can be executed by tricking an authenticated user, such as a shop administrator, into clicking a crafted link containing the malicious payload. Once the victim's browser executes the script, the attacker gains the ability to perform actions permitted by the victim's current session privileges.\nIn a post-exploitation scenario, the attacker can leverage this execution context to access sensitive data, such as authentication tokens or session identifiers, which are then transmitted to an attacker-controlled remote server.\nThe vulnerability affects Midtrans-WooCommerce versions 2.32.3 and earlier. It is categorized as a Reflected XSS vulnerability, requiring the victim to interact with the crafted malicious link to trigger the payload execution. The lack of sufficient server-side input sanitization across relevant plugin functions allows this bypass of security controls, making it possible for attackers to facilitate XSS attacks against the WordPress environment without needing an account on the target system."
}
CVE-2026-39758: Midtrans-WooCommerce Unauthenticated Reflected XSS (HIGH Severity, CVSS: 7.1) | Sceawere