Sceawere

Vulnerability Detail

CVE-2026-93512UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in JW Player

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
ilGhera
Product
JW Player for WordPress
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:21.997Z",
  "pubdate": "2026-09-30T13:17:21.997Z",
  "executiveSummary": "The JW Player for WordPress plugin, specifically versions 2.3.11 and below, contains a critical vulnerability involving Unauthenticated Cross-Site Scripting (XSS).\nThis flaw allows remote, unauthenticated attackers to inject malicious scripts into the web application, which are subsequently executed within the context of a victim's browser session.\nThe primary risk implications include session hijacking, unauthorized actions performed on behalf of authenticated administrators, and the potential for site-wide defacement or redirection to malicious domains.\nBecause the vulnerability is unauthenticated, no prior access or interaction with the WordPress administrative dashboard is required for exploitation.\nSuccessful execution of this attack compromises the security integrity of the victim's interaction with the WordPress site and poses a significant threat to user data confidentiality and account security.\nThis vulnerability highlights a failure in input sanitization or output encoding mechanisms within the plugin's data handling routines.",
  "technicalDetails": "The vulnerability manifests as an Unauthenticated Stored or Reflected Cross-Site Scripting (XSS) flaw, stemming from the improper sanitization of user-supplied input before rendering it in the browser.\nIn versions 2.3.11 and below of JW Player for WordPress, the plugin fails to adequately sanitize parameters or data inputs that are subsequently reflected back to the user within the HTML response context.\nThe root cause is likely the lack of rigorous input validation and the absence of context-aware output encoding. When an attacker crafts a malicious request containing script tags or event handlers (e.g., onerror, onload) within the vulnerable input vector, the application reflects this input directly into the Document Object Model (DOM).\nThe attack flow typically follows a predictable pattern: 1) The attacker identifies a vulnerable parameter processed by the plugin. 2) The attacker submits a malicious payload designed to bypass basic filters or utilize specific HTML tags permitted by the application. 3) The application, failing to encode the payload, includes the malicious script in the rendered page output. 4) A victim, such as a WordPress administrator or a standard user, navigates to the affected page, causing the browser to interpret and execute the attacker's JavaScript code.\nBecause the exploit does not require authentication, it is highly accessible, allowing an attacker to target any visitor to the site. The payload executes with the privileges of the victim's session. If an administrator visits the compromised page, the injected script could be used to create new administrative accounts, alter plugin settings, or exfiltrate sensitive configuration data, including nonces or session cookies.\nThe persistence of this attack depends on whether the reflected input is stored (Stored XSS) or immediately returned in a request (Reflected XSS). In both instances, the impact remains severe as it bypasses the browser's Same-Origin Policy (SOP) regarding script execution on the origin domain. The lack of Content Security Policy (CSP) headers or their inadequate configuration further facilitates the successful execution of these injected scripts, allowing the attacker to interact with the DOM, perform background AJAX requests to the WordPress API, and exfiltrate information to external command-and-control servers."
}
CVE-2026-93512: Unauthenticated XSS in JW Player (HIGH Severity, CVSS: 7.1) | Sceawere