Sceawere

Vulnerability Detail

CVE-2026-92712UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ReactPress Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
3h ago
Vendor
rockiger
Product
ReactPress – Create React App for WordPress
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents().

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-09-30T09:17:16.477Z",
  "pubdate": "2026-09-30T09:17:16.477Z",
  "executiveSummary": "The ReactPress – Create React App for WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 3.4.0.\nThe vulnerability arises from improper handling of the 'permalink' parameter, which fails to adequately sanitize user-supplied input.\nThe impact allows authenticated attackers with subscriber-level privileges or higher to inject arbitrary malicious web scripts into the application.\nWhen a victim, such as an administrator or another user, accesses a page containing the injected content, the malicious script executes within their browser context.\nThis represents a significant security risk, as successful exploitation can lead to unauthorized actions, session hijacking, or the defacement of the affected WordPress site.\nThe flaw stems from the plugin's reliance on 'sanitize_url()' to validate remote URLs, which proves insufficient in preventing the fetching and subsequent local storage of attacker-controlled content.\nBy leveraging this mechanism, attackers can facilitate the execution of arbitrary JavaScript, potentially compromising the integrity and security of the WordPress instance.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the 'permalink' parameter processing logic to perform adequate input sanitization or output encoding. The plugin utilizes the 'sanitize_url()' function to validate the user-provided 'permalink' input; however, this function is designed for URL structure validation rather than content integrity verification. It does not inspect the contents of the target URL.\nThe exploitation flow begins when an authenticated attacker, holding at least subscriber-level access, submits a malicious payload via the 'permalink' parameter. The plugin fetches the remote resource associated with the attacker-supplied URL.\nUpon fetching the content, the plugin uses the 'file_put_contents()' function to write the response body directly to the local disk. Because the remote content is written verbatim, an attacker can host a malicious script on an external server and point the 'permalink' parameter to that URL. The remote content, which can include <script> tags or HTML elements with malicious event-handler attributes (e.g., 'onload' or 'onerror'), is then saved as a local file by the WordPress environment.\nSubsequent access to the injected page causes the server to render the stored, malicious content. As this content is served directly from the WordPress environment, it executes within the victim's browser session. This mechanism bypasses standard browser-side defenses that might otherwise block cross-origin requests, as the payload is effectively treated as a local resource.\nThe post-exploitation impact includes the execution of arbitrary JavaScript in the context of the victim's session. This facilitates a wide range of malicious activities, including the theft of session cookies, the manipulation of the Document Object Model (DOM), the initiation of unauthorized administrative actions on the WordPress backend, or the redirection of users to external malicious domains.\nBecause the plugin does not implement strict allow-listing for the target domains or enforce content-type verification for the retrieved data, the vulnerability remains trivial to exploit for any authenticated user. The lack of output encoding ensures that any injected scripts within the retrieved file are rendered and executed immediately by the browser, confirming the stored XSS vulnerability."
}
CVE-2026-92712: ReactPress Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.4) | Sceawere