Sceawere

Vulnerability Detail

CVE-2026-88905UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

KeyWord Collector Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Unknown
Product
KeyWord Collector
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-11T07:17:27.493Z",
  "pubdate": "2026-10-11T07:17:27.493Z",
  "executiveSummary": "The KeyWord Collector WordPress plugin (through version 1.4) contains a critical Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and a complete lack of access control mechanisms.\nThe vulnerability allows an unauthenticated remote attacker to inject and persist malicious JavaScript payloads within the plugin's settings database.\nThis flaw stems from the application failing to implement nonce verification or administrative capability checks during the settings update process, effectively bypassing WordPress security architecture.\nThe impact is significant, as the injected scripts are executed within the browser context of any user who accesses the plugin settings or views the plugin output, including high-privileged administrators.\nSuccessful exploitation facilitates unauthorized actions, session hijacking, credential theft, or further administrative compromise of the WordPress installation.\nThe risk is critical given the absence of authentication requirements, allowing exploitation by any external network entity without prior system knowledge or access credentials.",
  "technicalDetails": "The vulnerability resides within the administrative settings management module of the KeyWord Collector plugin, specifically in the mechanism responsible for handling POST requests to update plugin configurations.\nThe root cause is twofold: a missing nonce verification and the absence of authorization checks (e.g., current_user_can() checks), which enables an unauthenticated attacker to interact with sensitive administrative functionality.\nWhen an attacker sends a crafted request to the plugin's settings endpoint, the backend process fails to validate the origin of the request or the authorization level of the sender. Consequently, the input is accepted by the plugin and persisted directly into the WordPress options table without any context-aware output encoding or sanitization.\nThe attack flow proceeds as follows: First, the attacker identifies the endpoint associated with the plugin's settings update. Second, the attacker constructs a malicious payload containing JavaScript, such as '<script>alert(document.cookie)</script>', and submits this payload via a crafted HTTP POST request to the plugin settings URL. Because no nonce validation is performed, the CSRF protections are effectively bypassed.\nUpon successful injection, the payload resides permanently in the database. The vulnerability manifests in two distinct contexts: First, when an administrator navigates to the plugin settings page, the plugin renders the stored input without escaping, triggering the execution of the injected script in the administrator's browser context. Second, if the plugin displays this input on the frontend of the site, any visitor loading the page will also execute the malicious payload.\nThe lack of sanitization allows for the injection of arbitrary HTML and JavaScript, enabling an attacker to perform unauthorized administrative actions, intercept session tokens, or execute malicious redirection scripts. Because the script executes within the security context of the user viewing the data, it bypasses standard client-side protections. The attack surface is broad as it does not require prior authentication or elevated privileges, making it accessible to any user capable of reaching the web server. Post-exploitation impact ranges from administrative account takeover to complete site defacement or the implementation of persistent backdoors via JavaScript-driven administrative panel actions."
}
CVE-2026-88905: KeyWord Collector Stored XSS (HIGH Severity, CVSS: 8.8) | Sceawere