Sceawere
Vulnerability Detail
CVE-2026-42634UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Video Background Block
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- bPlugins
- Product
- Video Background Block – Use video as background in the section.
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:55.047Z",
"pubdate": "2026-10-06T09:17:55.047Z",
"executiveSummary": "The Video Background Block plugin, specifically versions 2.0.3 and earlier, contains an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw stems from the improper sanitization of user-supplied input before rendering it in the application's interface.\nA remote, unauthenticated attacker can exploit this vulnerability by crafting a malicious URL containing a payload, which is then executed within the browser session of a victim who accesses the link. The impact of successful exploitation includes the execution of arbitrary JavaScript, potential theft of session tokens, session hijacking, defacement of the website, or redirection to malicious third-party domains.\nGiven that the vulnerability requires no authentication and can be triggered via a standard GET or POST request, the risk profile is significant. It facilitates client-side attacks against both administrative and standard users, potentially leading to privilege escalation or unauthorized administrative actions if an authenticated session is hijacked. There are no specific complex exploitation requirements beyond convincing an authenticated user to click a specially crafted link.",
"technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw located within the Video Background Block plugin. The root cause is the insufficient implementation of input sanitization and output encoding mechanisms for parameters processed by the plugin's frontend rendering engine.\nSpecifically, the plugin fails to sanitize user-provided data before reflecting it back into the Document Object Model (DOM) of the page. Because the application processes these inputs without proper escaping, an attacker can inject malicious script tags or event handlers—such as 'onmouseover', 'onerror', or 'onload'—that the browser will execute in the context of the user's session.\nThe attack flow follows a predictable sequence: First, the attacker identifies the vulnerable parameter used by the Video Background Block to display background configuration settings. Second, the attacker crafts a malicious URI containing an HTML or JavaScript payload. Third, the attacker distributes this link to targeted users, potentially via social engineering or embedded iframes. When an authenticated user clicks the link, the server processes the input and reflects the malicious script in the response. Finally, the user's browser parses the reflected content, executing the arbitrary JavaScript within the legitimate domain's security origin.\nThe vulnerability is present in versions <= 2.0.3 of the Video Background Block. Exploitation does not require prior authentication or elevated privileges, making it accessible to any external network actor. The payload execution is limited only by the victim's browser security settings and the specific context in which the input is reflected. Post-exploitation impact ranges from sensitive cookie exfiltration (where 'HttpOnly' flags are absent) to unauthorized API calls performed on behalf of the victim, which may lead to full account takeover if the victim possesses administrative roles. The lack of proper Content Security Policy (CSP) headers or robust input filtering on the vulnerable component significantly lowers the barrier for successful exploitation, allowing the script to manipulate page elements and perform actions without the user's consent."
}