Sceawere

Vulnerability Detail

CVE-2026-57806UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Martfury Reflected XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
drfuri
Product
Martfury - WooCommerce Marketplace WordPress Theme
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in drfuri Martfury - WooCommerce Marketplace WordPress Theme martfury allows Reflected XSS.This issue affects Martfury - WooCommerce Marketplace WordPress Theme: from n/a through 3.3.9.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-10T19:16:58.787Z",
  "pubdate": "2026-10-10T19:16:58.787Z",
  "executiveSummary": "The Martfury - WooCommerce Marketplace WordPress Theme, versions n/a through 3.3.9, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and execute arbitrary malicious scripts within the context of a victim's browser session.\nThe vulnerability poses significant risk to site administrators and end-users, as successful exploitation can lead to unauthorized actions performed on behalf of the user, theft of sensitive session cookies, session hijacking, and the potential redirection of users to malicious third-party domains. Because the reflection occurs within the victim's browser, the attacker requires no elevated privileges to initiate the attack; however, they must convince an authenticated or unauthenticated user to interact with a crafted malicious URL.\nThis vulnerability is particularly critical for e-commerce platforms like Martfury, where the compromise of administrative sessions or customer data can have severe financial and reputational consequences. The absence of adequate input validation and output encoding mechanisms at the application level remains the primary threat vector.",
  "technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The root cause resides in the theme's failure to adequately sanitize or escape user-supplied parameters before reflecting them into the HTML document structure during the rendering process.\nIn a reflected XSS attack flow, the attacker identifies an input parameter—typically passed via a GET request—that is unsafely rendered on the page by the Martfury theme. The attacker constructs a malicious payload, such as '<script>alert(document.cookie)</script>', and embeds it into the vulnerable URL parameter. When a victim clicks the crafted link, the web application includes the malicious script in the response sent to the user's browser.\nThe browser, unable to distinguish between legitimate application code and the injected malicious script, executes the payload within the security context of the origin. This allows the script to access the Document Object Model (DOM), intercept session tokens stored in document.cookie, perform unauthorized API requests, or modify page content to facilitate phishing or drive-by-download attacks.\nThe exploitation process typically follows these steps: 1) Identification of an unsanitized input field handled by the theme's templates. 2) Creation of a malicious URL containing a JavaScript payload encoded within the query string. 3) Delivery of this URL to a target user, often via social engineering, phishing, or public forums. 4) The user's browser processes the malicious request, reflecting the script into the DOM. 5) Execution of the payload, resulting in full control over the client-side session context.\nBecause this is a reflected vulnerability, it does not require the attacker to modify the server-side database. The payload is transient and exists only for the duration of the request/response cycle. However, the impact is persistent regarding the victim's session integrity. The affected versions (n/a through 3.3.9) lack the necessary output encoding functions—such as those provided by WordPress's esc_html(), esc_attr(), or esc_js()—on the vulnerable endpoints, rendering the application highly susceptible to payload injection through standard HTTP request parameters."
}
CVE-2026-57806: Martfury Reflected XSS Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere