Sceawere

Vulnerability Detail

CVE-2026-94081UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Persistent Login XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
lukeseager
Product
WordPress Persistent Login
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:23.523Z",
  "pubdate": "2026-09-30T13:17:23.523Z",
  "executiveSummary": "The WordPress Persistent Login plugin, in versions 3.1.3 and below, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw allows remote, unauthenticated attackers to inject arbitrary malicious JavaScript or HTML into web pages rendered by the application.\nThe vulnerability exists due to improper sanitization of user-supplied data before it is reflected back to the browser. Successful exploitation permits an attacker to execute malicious scripts in the context of an unsuspecting user's session. Depending on the target, this may result in unauthorized actions performed on behalf of authenticated users, session hijacking, or the defacement of the website. The impact is significant, as it bypasses standard access controls to facilitate client-side attacks.\nGiven the nature of XSS, the vulnerability carries a high risk for organizations using the plugin, as it does not require prior authentication to execute. Users and administrators are urged to prioritize remediation to prevent potential account takeovers and unauthorized administrative modifications.",
  "technicalDetails": "The vulnerability stems from an insecure implementation of data handling within the WordPress Persistent Login plugin (<= 3.1.3). The core issue is identified as an Improper Neutralization of Input During Web Page Generation, classified under CWE-79. The plugin fails to adequately sanitize or encode input parameters before rendering them in the browser environment, allowing for the injection of malicious payloads.\nThe exploitation flow begins with an unauthenticated attacker identifying a vulnerable entry point within the plugin's functionality that reflects input without proper validation. The attacker constructs a malicious payload, typically containing JavaScript encapsulated in script tags or HTML attributes designed to execute code. This payload is then submitted via HTTP GET or POST requests directed at the vulnerable component of the plugin.\nBecause the application does not implement robust output encoding, the server reflects the malicious payload back to the client-side of the application. When a user—who may be a privileged administrator or a standard site visitor—accesses the affected page, the browser interprets the injected script as legitimate code originating from the site. Consequently, the script executes within the security context of the victim's session.\nThe technical impact of this execution is broad. Attackers can leverage the script to access sensitive session cookies (if not protected by the HttpOnly flag), perform unauthorized administrative tasks via forged requests (Cross-Site Request Forgery), redirect users to malicious third-party domains, or exfiltrate sensitive data displayed on the page. Since the vulnerability is unauthenticated, it significantly lowers the barrier to entry for adversaries who aim to compromise site integrity or gain unauthorized access to user accounts.\nThe flaw affects versions 3.1.3 and earlier, indicating that the vulnerability resides in the core handling logic of the plugin's persistent authentication mechanisms. Without proper input validation or context-aware output encoding (such as the use of esc_html() or esc_attr() within the WordPress framework), the plugin effectively facilitates the delivery of malicious content to the user's browser, bypassing established web security controls."
}
CVE-2026-94081: Unauthenticated Persistent Login XSS (HIGH Severity, CVSS: 7.1) | Sceawere