Sceawere

Vulnerability Detail

CVE-2026-68567UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Convert Pro Unauthenticated XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
WP Grids
Product
Convert Pro
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T15:17:00.527Z",
  "pubdate": "2026-08-18T15:17:00.527Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in the Convert Pro plugin, affecting versions 1.0.1 and prior. This security flaw enables remote attackers to inject malicious client-side scripts, typically written in JavaScript, into vulnerable web pages rendered by the application.\nThe primary impact of this vulnerability includes session hijacking, credential theft, malicious redirection, and defacement of the affected WordPress site. Because the vulnerability is unauthenticated, threat actors require no prior access or privileges to launch an attack, significantly increasing the risk profile for installations running vulnerable software versions.\nExploitation relies on the application failing to properly sanitize or encode user-supplied input before reflecting it back to the client browser. Successful exploitation occurs entirely within the context of the victim's browser session, allowing attackers to interact with the web application with the privileges of the affected user.\nOrganizations utilizing the affected versions of Convert Pro face substantial risk exposure, as automated exploitation vectors can rapidly target exposed instances across the internet. Immediate remediation is necessary to prevent unauthorized code execution and maintain the integrity and confidentiality of the web application environment.",
  "technicalDetails": "The vulnerability is classified as an Unauthenticated Cross-Site Scripting (XSS) flaw residing within the Convert Pro product in versions 1.0.1 and below. The root cause of the issue stems from insufficient input sanitization and improper output encoding of user-controlled parameters handled by the plugin.\nNetwork exposure is fully external, as the vulnerable entry points are accessible via standard HTTP/HTTPS requests over the web without requiring any authentication or authorization mechanisms. Consequently, any remote attacker can craft a malicious HTTP request containing a payload designed to trigger the XSS condition.\nThe attack flow proceeds as follows: First, the attacker identifies a vulnerable parameter or endpoint within the Convert Pro plugin that processes and reflects unvalidated input. Second, the attacker crafts a malicious payload incorporating executable JavaScript or HTML tags. Third, the attacker delivers this payload to the target via a crafted URL or direct HTTP request. Fourth, when a victim accesses the manipulated application state or the server reflects the input in the Hypertext Markup Language (HTML) response, the browser executes the injected script in the context of the victim's session.\nPayload behavior involves executing arbitrary JavaScript within the Document Object Model (DOM) of the vulnerable site. This permits the attacker to access sensitive document properties, including cookies and session tokens, manipulate page content, or initiate unauthorized asynchronous requests via the Fetch API or XMLHttpRequest.\nPrivilege requirements are nonexistent (unauthenticated), meaning an external threat actor can execute the attack vector independently of user roles. Post-exploitation impact encompasses potential administrative account compromise if an authenticated administrator views the payload, leading to full site takeover, arbitrary file manipulation, and persistent backdoor deployment."
}
CVE-2026-68567: Convert Pro Unauthenticated XSS Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere