Sceawere
Vulnerability Detail
CVE-2026-39780UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Youzify
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- Youzify
- Product
- Youzify
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:50.647Z",
"pubdate": "2026-10-06T09:17:50.647Z",
"executiveSummary": "Youzify versions 1.3.7 and below contain an unauthenticated Cross-Site Scripting (XSS) vulnerability.\nThis flaw allows remote, unauthenticated attackers to inject malicious scripts into the web application, which are then executed in the browser context of unsuspecting users, including administrative personnel.\nThe vulnerability stems from improper neutralization of user-supplied input before rendering it in the UI.\nThe primary impact includes session hijacking, credential theft, redirection to malicious domains, and unauthorized modification of the application state or content.\nAs the vulnerability does not require authentication, it significantly increases the attack surface, enabling widespread exploitation against site visitors and logged-in users without prior system access.\nThe risk is categorized as high due to the potential for full account takeover and the ability to conduct targeted phishing or drive-by download attacks using the trusted domain of the vulnerable instance.",
"technicalDetails": "The vulnerability is identified as a Stored or Reflected Cross-Site Scripting (XSS) flaw within the Youzify plugin for WordPress, specifically affecting versions 1.3.7 and earlier.\nThe root cause of this vulnerability is the failure of the application to adequately sanitize or encode input parameters before reflecting them back to the user's browser, or storing them in the database for later retrieval.\nIn a typical attack flow, an adversary crafts a malicious URL containing a JavaScript payload within vulnerable input fields. When an unsuspecting user, such as an administrator, clicks this link or visits the affected page, the server processes the request and reflects the malicious script in the HTML response without appropriate character escaping.\nBecause the payload is delivered in the context of the vulnerable domain, the browser executes the script as a trusted component of the site. This bypasses typical Same-Origin Policy (SOP) restrictions that would otherwise prevent cross-site interactions.\nThe attack is characterized as unauthenticated, meaning the attacker does not need to possess any privileges, roles, or a registered account on the Youzify-powered system. The exposure is limited only by the attacker's ability to reach the vulnerable endpoint via the network.\nSuccessful exploitation allows for the execution of arbitrary JavaScript code. Common post-exploitation payloads include stealing session cookies (document.cookie), performing unauthorized administrative actions, or modifying the document object model (DOM) to present fake login prompts to users.\nGiven that administrative users are often the target for such exploits, an attacker can effectively elevate their access to a full system compromise by seizing an active admin session or injecting persistent backdoors, such as rogue administrator accounts or malicious plugin files, into the underlying WordPress environment.\nThe vulnerability demonstrates a lack of rigorous input validation and output encoding protocols within the plugin's core functions responsible for data handling. By failing to filter sensitive characters such as <, >, \", and ', the plugin creates a direct vector for script injection into the client-side environment."
}