Sceawere
Vulnerability Detail
CVE-2026-93514UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Notification for Telegram
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- rainafarai
- Product
- Notification for Telegram
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:22.130Z",
"pubdate": "2026-09-30T13:17:22.130Z",
"executiveSummary": "Notification for Telegram versions 3.5.2 and below are vulnerable to an unauthenticated Cross-Site Scripting (XSS) vulnerability.\nThe vulnerability resides in the improper handling of user-supplied input, allowing an unauthenticated remote attacker to inject malicious JavaScript into the application's administrative or frontend interface.\nSuccessful exploitation allows for the execution of arbitrary scripts within the context of the victim's session.\nThe impact includes potential session hijacking, unauthorized administrative actions, sensitive data theft, and the redirection of users to malicious third-party domains.\nThis vulnerability is critical due to its unauthenticated nature, meaning no prior access or user interaction from an authenticated account is required to trigger the payload.\nOrganizations relying on Notification for Telegram are at risk of complete compromise of affected administrative sessions.",
"technicalDetails": "The vulnerability is identified as a Stored or Reflected Cross-Site Scripting (XSS) flaw, stemming from the application's failure to adequately sanitize or encode input fields before rendering them in the browser.\nIn versions 3.5.2 and earlier, the Notification for Telegram plugin processes incoming notification data or configuration parameters without applying necessary security controls such as context-aware output encoding or input validation.\nThe attack flow begins when an attacker crafts a malicious HTTP request containing a JavaScript payload within parameters that are later reflected or stored by the plugin.\nBecause the vulnerability is unauthenticated, the attacker does not require valid credentials to submit these malicious payloads. Upon receipt of the request, the application persists or directly embeds the payload into the Document Object Model (DOM) of the target interface.\nWhen a legitimate user, such as a site administrator, views the notification logs or the plugin configuration page, the malicious script executes within the victim's browser context.\nThe execution context is bound by the victim's session cookies and permissions, granting the attacker the same level of access as the victim.\nPost-exploitation activities include, but are not limited to, the extraction of CSRF tokens to perform unauthorized administrative modifications, the exfiltration of sensitive configuration data to an external server controlled by the attacker, or the injection of additional persistent hooks (e.g., web shells or administrative accounts) into the underlying CMS.\nThe lack of Content Security Policy (CSP) headers or strict input filtering allows the browser to interpret the injected script as legitimate code originating from the trusted domain.\nGiven that the plugin handles notifications, the attack vector is likely exposed to the public internet, increasing the likelihood of automated exploitation by malicious actors scanning for vulnerable WordPress or web service deployments."
}