Sceawere
Vulnerability Detail
CVE-2026-95817UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in DoFollow Case by Case
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 15h ago
- Vendor
- apasionados
- Product
- DoFollow Case by Case
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T08:17:03.933Z",
"pubdate": "2026-10-02T08:17:03.933Z",
"executiveSummary": "The DoFollow Case by Case plugin for WordPress, in all versions up to and including 3.6.0, contains a critical security flaw involving Stored Cross-Site Scripting (XSS).\nThe vulnerability arises from improper sanitization of user-supplied data within comment content, allowing unauthenticated attackers to inject malicious scripts into the application.\nThe impact is significant, as successful exploitation enables the execution of arbitrary JavaScript in the browsers of users viewing the compromised content, including site administrators.\nWhile comment moderation serves as a deterrent, it does not mitigate the risk, as the payload remains stored until authorized by an administrator.\nThis vulnerability poses a substantial threat to site integrity and user session security, potentially leading to unauthorized actions, account takeover, or the redirection of visitors to malicious external sites.\nNo specific privileges are required for the initial injection, and the attack vector is exposed to any user capable of posting comments on the target WordPress installation.",
"technicalDetails": "The root cause of this vulnerability is the lack of server-side input sanitization and context-aware output escaping within the DoFollow Case by Case plugin's comment handling logic.\nBy failing to filter malicious scripts from comment input, the plugin permits the persistence of arbitrary HTML and JavaScript tags directly into the WordPress database.\nThe attack flow begins when an unauthenticated attacker submits a comment containing a crafted malicious script payload to a post managed by the affected plugin.\nThe payload is stored in the database associated with the post. If the WordPress environment requires administrator approval for comments, the payload remains in a pending state, appearing visually innocuous to the moderator.\nOnce the administrator approves the comment, the payload is rendered globally on the front-end of the website for all subsequent visitors.\nWhen a user or administrator navigates to the affected post, the victim's web browser automatically interprets the stored script as legitimate code originating from the trusted domain.\nThe injected script executes within the context of the user's browser session, granting the attacker the ability to perform unauthorized actions on behalf of the victim, such as modifying site content, stealing session cookies, or intercepting sensitive information.\nBecause the execution happens in the visitor's browser, the security boundary between the web application and the client is effectively circumvented.\nThe vulnerability is present in all versions up to and including 3.6.0, indicating a persistent failure to implement security best practices such as utilizing WordPress-native sanitization functions like sanitize_text_field() or esc_html() during output rendering.\nThis Stored XSS vector is particularly dangerous because it does not require prior authentication, making it accessible to any individual who can interact with the plugin-enabled comment section."
}