Sceawere
Vulnerability Detail
CVE-2026-96332UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Simple Payment Reflected XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- yalla ya!
- Product
- Simple Payment
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yalla ya! Simple Payment simple-payment allows Reflected XSS.This issue affects Simple Payment: from n/a through 2.5.4.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:44.320Z",
"pubdate": "2026-10-09T10:16:44.320Z",
"executiveSummary": "The Simple Payment plugin for WordPress, developed by yalla ya!, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw stems from the improper neutralization of user-supplied input before it is rendered in the web page, allowing an attacker to inject arbitrary malicious scripts.\nThe vulnerability affects all versions of Simple Payment from inception through 2.5.4. Successful exploitation permits an attacker to execute unauthorized JavaScript in the context of a victim's browser session. This can lead to the theft of session cookies, unauthorized actions performed on behalf of the user, redirection to malicious domains, or the exfiltration of sensitive information presented on the compromised page.\nThe impact is categorized as high, as it bypasses standard client-side security controls. Exploitation typically requires the victim to interact with a crafted link provided by the attacker. No specialized authentication is inherently required to initiate the attack, making it a significant risk for administrative or customer-facing interfaces using the plugin.",
"technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw caused by insufficient input validation and output encoding in the Simple Payment plugin. The root cause lies in the application's failure to sanitize parameters passed via HTTP GET or POST requests before echoing them back into the HTML response generated for the client.\nIn a typical attack flow, an attacker identifies a vulnerable parameter within the Simple Payment functionality that is reflected in the HTTP response. The attacker constructs a malicious URL containing a payload—typically a script tag or event handler—within this parameter. When an authenticated or unauthenticated user clicks this crafted link, the malicious payload is sent to the server.\nThe server processes the request and embeds the unvalidated input directly into the generated HTML document. Upon receipt, the victim's browser interprets the injected data as legitimate executable code. Because the script executes within the origin of the vulnerable site, it inherits the session's privileges and access rights. This enables the script to manipulate the Document Object Model (DOM), perform unauthorized cross-origin requests, or steal sensitive data such as CSRF tokens or authentication cookies if the 'HttpOnly' flag is not strictly enforced.\nThe vulnerability is inherent to the plugin's core handling of input parameters, affecting versions up to and including 2.5.4. Exploitation does not necessarily require administrative privileges, though the impact is maximized when the victim is an administrator, potentially leading to full site compromise via the execution of administrative functions in the background. The lack of robust context-aware output encoding remains the primary driver of this flaw, allowing for the bypass of rudimentary filters if any were present. As the plugin is used to handle payment-related data, the risk of capturing sensitive transaction details during an active XSS session is a critical concern for both the site owner and the end user."
}