Sceawere

Vulnerability Detail

CVE-2026-66456UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Profile Extra Fields XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
bestwebsoft
Product
Profile Extra Fields by BestWebSoft
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T14:17:06.697Z",
  "pubdate": "2026-08-13T14:17:06.697Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the Profile Extra Fields plugin developed by BestWebSoft, specifically affecting versions 1.3.4 and prior. This security flaw allows authenticated users with subscriber-level privileges to inject and execute arbitrary client-side scripts, such as malicious JavaScript, within the context of other users' browsers. The vulnerability impacts the integrity and confidentiality of the affected web application by potentially exposing session tokens, sensitive user data, or allowing unauthorized actions on behalf of other victims interacting with the injected profile fields. The risk implications include potential session hijacking, defacement, and further compromise of administrative or high-privileged accounts if administrators view the malicious payload. Exploitation requires authenticated subscriber access to the application, specifically the capability to modify or interact with profile extra fields, meaning an attacker must first obtain valid low-privileged credentials to mount an attack.",
  "technicalDetails": "The vulnerability is rooted in insufficient input sanitization and output encoding within the Profile Extra Fields plugin by BestWebSoft for versions <= 1.3.4. Specifically, user-supplied data provided within profile extra fields is improperly handled when rendered back to the user interface, allowing stored or reflected script payloads to be interpreted and executed by the browser.\nThe affected component involves the handling and rendering mechanisms of profile extra fields where user input is processed without adequate contextual output encoding. Because the application fails to neutralize special characters such as angle brackets (< and >) and event handlers, arbitrary JavaScript payloads can be successfully injected into the Document Object Model (DOM).\nThe attack flow proceeds as follows: 1. An attacker authenticates to the target WordPress installation using a subscriber-level account. 2. The attacker navigates to the profile modification interface and submits a payload containing malicious JavaScript within the profile extra fields parameters. 3. The input is stored in the database without sufficient sanitization. 4. When a victim or a higher-privileged user, such as an administrator, views the affected profile page, the application retrieves the malicious input from the database and renders it directly into the HTML response without proper escaping. 5. The victim's browser executes the injected script within the security context of the vulnerable application, enabling actions such as session token theft, cookie exfiltration, or unauthorized API requests executed under the victim's session.\nThe vulnerability requires subscriber-level authentication and network exposure via the web application interface. Affected versions include all instances of Profile Extra Fields by BestWebSoft up to and including version 1.3.4. Post-exploitation impact depends heavily on the privileges of the user viewing the crafted profile fields, potentially leading to privilege escalation if an administrative session is compromised by the script payload."
}
CVE-2026-66456: Profile Extra Fields XSS Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere