Sceawere

Vulnerability Detail

CVE-2026-96351UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in Classified Listing

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
RadiusTheme
Product
Classified Listing
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:30.220Z",
  "pubdate": "2026-09-30T13:17:30.220Z",
  "executiveSummary": "The Classified Listing plugin for WordPress, in versions 6.1.3 and earlier, contains a critical security vulnerability involving improper neutralization of input during web page generation. This flaw permits unauthenticated remote attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThis vulnerability is classified as a Reflected or Stored Cross-Site Scripting (XSS) attack. The primary impact includes the potential for session hijacking, unauthorized actions performed on behalf of authenticated administrators or users, and the exfiltration of sensitive data stored in local storage or cookies.\nThe flaw stems from a failure to sanitize or escape user-supplied input before rendering it in the browser interface. Given that the vulnerability does not require authentication, an attacker can target any user of the application, including site administrators. The risk is considered high, as successful exploitation enables attackers to manipulate site content, redirect users to malicious domains, or deploy browser-based malware. Organizations utilizing versions 6.1.3 or lower are at immediate risk and should prioritize remediation efforts to prevent unauthorized access and potential compromise of the WordPress environment.",
  "technicalDetails": "The vulnerability exists due to insufficient input validation and output encoding within the Classified Listing plugin’s codebase. Specifically, the plugin fails to implement robust sanitization routines for parameters passed through HTTP GET or POST requests that are subsequently echoed in the application's response body.\nThe root cause is the improper handling of user-controllable input in the front-end rendering functions. When the plugin processes incoming request data, it fails to verify the integrity or content of the input, allowing characters such as <, >, \", and ' to be rendered without proper HTML entity encoding. An attacker can supply a crafted URL or form payload containing malicious script tags, which the server reflects back to the victim's browser.\nThe exploitation flow begins with the attacker crafting a malicious payload, typically embedded within a URL parameter. When an unsuspecting user, such as an administrator, clicks a link containing this payload or interacts with a manipulated form, the script is executed by the victim's browser. Because the victim's browser trusts the origin of the plugin, the script gains the ability to interact with the Document Object Model (DOM), access document.cookie (if not protected by HttpOnly flags), and perform background AJAX requests to the WordPress API or administrative dashboard.\nThe vulnerability affects all versions of Classified Listing up to and including 6.1.3. The attack is executable over the network (Internet-facing) and requires zero authentication, meaning the barrier to entry is extremely low. Attackers do not require elevated privileges to execute the payload, as the vulnerability resides in the application's public-facing interfaces.\nPost-exploitation, the attacker can achieve a range of malicious outcomes: session hijacking by stealing administrative cookies, performing unauthorized configuration changes within the WordPress dashboard, or distributing malicious payloads to other visitors. Furthermore, if the script is stored (persistent XSS), the attack remains active until the payload is manually removed from the database or the vulnerable code is patched to enforce strict output encoding."
}
CVE-2026-96351: Unauthenticated XSS in Classified Listing (HIGH Severity, CVSS: 7.1) | Sceawere