Sceawere

Vulnerability Detail

CVE-2026-94665UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Classified Listing

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Mamunur Rashid
Product
Classified Listing
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid Classified Listing classified-listing allows Stored XSS.This issue affects Classified Listing: from n/a through 6.1.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-09T10:16:41.557Z",
  "pubdate": "2026-10-09T10:16:41.557Z",
  "executiveSummary": "The Classified Listing plugin for WordPress contains a Stored Cross-site Scripting (XSS) vulnerability affecting versions up to 6.1.2.\nThe vulnerability arises from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and persist malicious JavaScript code within the application.\nSuccessful exploitation enables an attacker to execute arbitrary scripts in the browser of a victim, including administrative users.\nThe impact includes the potential for session hijacking, unauthorized actions performed on behalf of the user, sensitive data exfiltration, and site defacement.\nThe vulnerability requires the attacker to successfully inject malicious input that is later rendered by the application, typically requiring user interaction or elevated privileges depending on the specific input vector within the classified listing features.",
  "technicalDetails": "The vulnerability is identified as an improper neutralization of input during web page generation, leading to Stored XSS in the Classified Listing plugin.\nThe root cause of this vulnerability lies in the insufficient sanitization and escaping of user-provided data before it is stored in the database and subsequently rendered in the WordPress admin dashboard or front-end interface.\nWhen a user or attacker inputs malicious script tags or crafted HTML attributes into fields processed by the Classified Listing plugin, the application fails to adequately encode or sanitize the input.\nOnce the payload is saved in the database, it becomes persistent; every time the affected page or administrative panel renders the tainted data, the browser interprets the injected script as legitimate code.\nThe attack flow typically involves an attacker submitting a listing, profile field, or other input parameter handled by the plugin. By embedding a malicious payload such as <script>alert('XSS')</script> or using event handlers like onerror within HTML tags, the attacker ensures the payload triggers upon page load.\nBecause the payload is stored, the attack does not require immediate interaction from the victim at the time of injection, but rather executes when a victim views the affected component.\nAffected versions are documented from n/a through 6.1.2.\nThe scope of the impact is severe; if an administrative user views the injected content, the attacker could leverage the victim's session cookies to perform administrative actions, modify plugin settings, or escalate privileges.\nThe persistence of the payload distinguishes this from Reflected XSS, as the malicious code resides within the application's persistent storage, facilitating wide-scale impact depending on the visibility of the vulnerable listing or data field.\nThe vulnerability highlights a failure in following secure coding practices regarding input validation and output encoding, specifically concerning the handling of user-submitted content within the WordPress plugin ecosystem."
}
CVE-2026-94665: Stored XSS in Classified Listing (MEDIUM Severity, CVSS: 6.5) | Sceawere