Sceawere

Vulnerability Detail

CVE-2026-96450UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

pixfort Core Contributor XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
pixfort
Product
pixfort Core
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-30T13:17:30.487Z",
  "pubdate": "2026-09-30T13:17:30.487Z",
  "executiveSummary": "This vulnerability is classified as a Stored Cross-Site Scripting (XSS) flaw affecting the pixfort Core plugin in versions prior to 4.3.3. The security defect resides in the plugin's inadequate sanitization of user-supplied input provided by users with Contributor-level privileges.\nThe vulnerability allows an authenticated attacker to inject malicious JavaScript into the application, which is subsequently executed in the context of other users' sessions, including those with higher administrative privileges. Successful exploitation can lead to unauthorized access to sensitive data, session hijacking, or the execution of arbitrary actions on behalf of the victim. The attack requires authenticated access to the system, specifically at the Contributor role level, and leverages the lack of robust input validation mechanisms during content submission. Given the nature of XSS, the impact is significant, potentially compromising the integrity and confidentiality of the entire WordPress installation. Organizations utilizing affected versions are at risk of lateral movement and site-wide control if an administrative account interacts with the malicious payload.",
  "technicalDetails": "The root cause of this vulnerability is improper neutralization of input within the pixfort Core plugin, specifically regarding the handling of data submitted by Contributor-level users. In versions of pixfort Core < 4.3.3, the plugin fails to perform context-aware output encoding or rigorous server-side input validation on metadata or content fields processed by the plugin's internal functions.\nThe attack flow begins when an attacker, authenticated as a user with Contributor privileges, submits a crafted malicious payload via fields managed by the plugin. Because the plugin does not correctly sanitize these inputs, the malicious JavaScript is stored in the WordPress database. When a target user—typically an administrator or a user with higher permissions—views the affected post, page, or dashboard area where the stored data is rendered, the payload is executed automatically by the victim's browser.\nThe exploitation method relies on the DOM-based or Stored XSS vector, where the browser interprets the injected script as legitimate part of the page structure. Because the script executes within the context of the current user's session, it gains access to document cookies, local storage, and session tokens. An attacker can leverage this to perform unauthorized actions such as modifying site settings, creating new administrative accounts, or exfiltrating sensitive session identifiers via an out-of-band request to an attacker-controlled server.\nThe vulnerable component involves the logic responsible for processing and rendering user-defined settings or content blocks within the pixfort Core plugin. Since the plugin processes this input without adequate security controls, the application fails to distinguish between safe markup and executable scripts. This persistence ensures that the payload is triggered repeatedly whenever the affected element is rendered, maximizing the opportunity for successful exploitation. The requirement for authenticated access limits the initial entry vector to existing users, yet the escalation path remains critical, as it bypasses the security boundaries between Contributor and Administrator roles through client-side script execution."
}
CVE-2026-96450: pixfort Core Contributor XSS Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere