Sceawere

Vulnerability Detail

CVE-2026-94641UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

UsersWP Reflected XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Stiofan
Product
UsersWP
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan UsersWP userswp allows Reflected XSS.This issue affects UsersWP: from n/a through 1.2.73.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-09T10:16:41.020Z",
  "pubdate": "2026-10-09T10:16:41.020Z",
  "executiveSummary": "The UsersWP plugin for WordPress, within versions ranging from n/a through 1.2.73, contains a vulnerability classified as CWE-79: Improper Neutralization of Input During Web Page Generation, commonly referred to as Reflected Cross-Site Scripting (XSS).\nThe flaw exists due to inadequate sanitization and output encoding of user-supplied data reflected within the web application interface. This security gap permits unauthenticated or authenticated attackers to inject malicious client-side scripts into the victim's browser session.\nIf successfully exploited, an attacker can execute arbitrary JavaScript in the context of the user's browser, potentially leading to unauthorized actions, session hijacking, credential theft, or the redirection of users to malicious third-party domains.\nGiven that the vulnerability is reflected, the exploitation requires the victim to interact with a crafted link or resource containing the malicious payload. The overall risk is significant, as it impacts the integrity of user interactions with the affected WordPress environment.",
  "technicalDetails": "The vulnerability originates from the failure of the UsersWP plugin to correctly validate or sanitize input parameters before rendering them back into the HTML response. Specifically, the application reflects input received via HTTP GET or POST parameters into the DOM without implementing proper context-aware output encoding.\nIn the context of UsersWP, the vulnerable component processes user-provided parameters that are subsequently included in the generated web page. When a request containing a malicious payload—typically represented as a JavaScript snippet embedded within a URL parameter—is sent to the server, the application echoes this input directly into the browser's document object model (DOM).\nThe attack flow proceeds as follows: An attacker identifies an input vector within the plugin that is reflected in the server response. The attacker crafts a malicious URL containing a JavaScript payload (e.g., <script>alert(document.cookie)</script>) designed to trigger a specific action upon execution. The attacker induces a target user—typically an administrator or a privileged user—to click this link via social engineering or phishing tactics.\nUpon clicking the link, the victim's browser submits the request to the vulnerable UsersWP endpoint. The server processes the request and embeds the unencoded payload into the generated HTML. The victim's browser receives the malicious script as part of the page content and executes it within the security context of the origin domain.\nBecause the script executes in the victim's browser, it gains access to sensitive data such as document.cookie, localStorage, or session tokens. Furthermore, the attacker can use this vector to perform actions on behalf of the user, such as modifying plugin settings, creating new administrative accounts, or injecting malicious content into the site's database.\nThe vulnerability affects all versions of UsersWP from n/a up to and including 1.2.73. No specific authentication is required to initiate the reflection, although the impact is amplified if the victim possesses higher administrative privileges. The vulnerability is accessible over the network via standard HTTP/HTTPS protocols."
}
CVE-2026-94641: UsersWP Reflected XSS Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere