Sceawere
Vulnerability Detail
CVE-2026-39788UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Front End PM Subscriber XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 16h ago
- Vendor
- Shamim Hasan
- Product
- Front End PM
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T09:17:51.627Z",
"pubdate": "2026-10-06T09:17:51.627Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the Front End PM plugin for WordPress, affecting all versions up to and including 11.4.6.\nThe vulnerability is categorized as a Stored XSS flaw, allowing authenticated users with Subscriber privileges to inject malicious JavaScript into the application's front-end interface.\nImpact includes the potential for session hijacking, unauthorized actions performed on behalf of other users, and the redirection of victims to malicious domains.\nSuccessful exploitation requires the attacker to have at least a Subscriber-level account on the target WordPress installation.\nThe vulnerability arises from improper neutralization of user-supplied input before rendering it in the browser, failing to adequately sanitize data passed to the message system.\nRisk implications are significant, as an attacker can compromise administrative sessions if an administrator views the crafted message, leading to full site takeover.\nNo complex exploitation vectors are required; the flaw is triggered through the standard message composition interface provided by the plugin.",
"technicalDetails": "The Front End PM plugin suffers from an input sanitization failure within its message handling functionality. The application fails to strictly validate or escape user-supplied content within the message body or metadata fields, allowing for the injection of arbitrary HTML and JavaScript tags.\nThe root cause is identified as an insufficient sanitization process when processing incoming message requests from authenticated subscribers. When a user sends a message, the plugin stores the raw or improperly sanitized input into the database. When the recipient views the message, the application renders this content directly into the DOM without context-aware output encoding.\nThe attack flow proceeds as follows: 1. An attacker authenticated as a Subscriber constructs a message containing a malicious payload (e.g., <script>alert('XSS')</script> or event handlers like onload or onerror). 2. The attacker submits this message via the plugin's native interface. 3. The server accepts the payload and stores it in the database associated with the message thread. 4. When the target user (e.g., an administrator or another subscriber) accesses their inbox, the plugin fetches the stored message. 5. The application dynamically injects the stored payload into the victim's browser session. 6. The victim's browser executes the script within the security context of the affected site.\nBecause the payload is stored, this is classified as a Stored XSS attack. The script execution occurs automatically upon viewing the message, requiring no further interaction from the victim. The executed JavaScript operates under the victim's session cookies, granting the attacker the ability to make API calls, modify settings, or exfiltrate sensitive data available to the user.\nThe vulnerability is inherent in the plugin's core message processing functions, affecting versions 11.4.6 and earlier. Authentication is required to gain access to the messaging interface, but the privileges required are minimal (Subscriber). The attack is fully network-accessible as long as the user can interact with the message submission form.\nPost-exploitation impact is severe, as it facilitates unauthorized administrative actions, cross-site request forgery (CSRF) chains, and the theft of session tokens via document.cookie access."
}