Sceawere

Vulnerability Detail

CVE-2026-42635UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in WooCommerce Simple Auctions

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
wpgenie
Product
WooCommerce Simple Auctions
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:55.193Z",
  "pubdate": "2026-10-06T09:17:55.193Z",
  "executiveSummary": "The WooCommerce Simple Auctions plugin is susceptible to an Unauthenticated Cross-Site Scripting (XSS) vulnerability affecting versions 3.0.10 and earlier.\nThis vulnerability stems from improper neutralization of user-supplied input before rendering it in the browser, allowing an unauthenticated remote attacker to inject malicious JavaScript payloads.\nThe impact is significant, as successful exploitation enables attackers to execute arbitrary scripts in the context of an unsuspecting user's session.\nRisk implications include unauthorized access to sensitive session data, such as session cookies or authentication tokens, which can lead to account takeover.\nAttackers can leverage this flaw to perform actions on behalf of the victim, alter web page content, or redirect users to malicious third-party websites.\nThe vulnerability does not require authentication or elevated privileges, making it accessible to any remote attacker with network access to the target WordPress installation.\nOrganizations using affected versions of WooCommerce Simple Auctions are at risk of client-side attacks and should prioritize updates or apply compensating controls.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the WooCommerce Simple Auctions plugin to adequately sanitize and escape user-controllable input prior to outputting it within the web application interface.\nThis flaw characterizes a Reflected or Stored Cross-Site Scripting (XSS) vulnerability, where malicious payloads are processed and executed by the victim's browser.\nThe exploitation process typically involves an attacker crafting a malicious request containing a JavaScript payload. When a user interacts with the affected component—often through a crafted URL or by viewing a page containing the injected content—the malicious script executes.\nBecause the input is not properly validated against a secure allowlist or escaped using appropriate WordPress context-aware functions (e.g., esc_html(), esc_attr(), or esc_js()), the browser interprets the input as executable code rather than plain text.\nThe attack flow follows these steps: 1) The attacker identifies a vulnerable parameter or input field handled by the plugin. 2) The attacker injects a script tag or event handler payload into the input. 3) The server reflects this input back to the user's browser without sanitization. 4) The browser executes the injected script within the security context of the origin site.\nThis vulnerability is classified as unauthenticated, meaning no prior session or administrative access is required to initiate the attack. The attack surface is restricted only by the availability of the vulnerable endpoint via the web server.\nSuccessful exploitation allows for a broad range of post-exploitation activities. By accessing the DOM of the vulnerable page, an attacker can steal sensitive data, modify the user interface to facilitate phishing (e.g., credential harvesting), or perform unauthorized API calls to the WordPress backend if the victim has administrative privileges.\nThe scope of impact is limited to the client-side, but the consequences are severe given the potential for session hijacking, which effectively bypasses standard authentication mechanisms.\nThe affected versions include 3.0.10 and all prior iterations of the WooCommerce Simple Auctions plugin that share this insecure handling of user input."
}
CVE-2026-42635: Unauthenticated XSS in WooCommerce Simple Auctions (HIGH Severity, CVSS: 7.1) | Sceawere