Sceawere

Vulnerability Detail

CVE-2026-96682UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Presto Player Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2h ago
Vendor
2winfactor
Product
Presto Player
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via <presto-player> Tag in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an initial comment approval, though WordPress default settings will auto-approve all subsequent comments from the same author, allowing a patient unauthenticated attacker to land the payload without further admin intervention.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T06:16:45.387Z",
  "pubdate": "2026-10-10T06:16:45.387Z",
  "executiveSummary": "The Presto Player plugin for WordPress contains a critical Stored Cross-Site Scripting (XSS) vulnerability residing within its comment handling functionality.\nThe vulnerability is triggered by the improper sanitization and output escaping of the <presto-player> shortcode tag when used within comment content.\nThis flaw permits unauthenticated remote attackers to inject and execute arbitrary JavaScript code within the context of the victim's browser.\nThe impact includes potential unauthorized access to sensitive user data, session hijacking, and the ability to perform actions on behalf of authenticated administrators or users.\nWhile the initial injection requires comment approval, the exploit is significantly augmented by WordPress's default 'comment author previously approved' mechanism, which allows subsequent payloads from the same identifier to bypass moderation filters.\nAffected products include all versions of the Presto Player plugin up to and including version 4.5.1.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the WordPress installation and its user base.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting, arising from a failure to adequately validate and sanitize user-supplied input submitted via the WordPress comment system.\nSpecifically, the plugin fails to enforce strict input filtering or contextual output encoding for the <presto-player> tag when it is rendered on the frontend.\nThe root cause is the plugin's internal parsing logic for the <presto-player> shortcode, which processes the attributes or content of the tag without validating the inclusion of potentially malicious HTML or script structures.\nWhen an unauthenticated attacker submits a comment containing a crafted <presto-player> tag with malicious attributes or inner content, the plugin processes this string and stores it in the WordPress database.\nWhen a user, such as an administrator or subscriber, views the page containing the malicious comment, the plugin renders the content without adequate output escaping.\nThis causes the browser to treat the injected payloads as executable script tags or attribute-based JavaScript triggers rather than plain text.\nThe attack flow follows a structured path: first, the attacker crafts a payload utilizing the <presto-player> shortcode to host an XSS vector. Second, the attacker submits the comment. If the comment moderation settings are set to require approval, the initial entry must be manually approved, or the attacker must wait for a subsequent comment from the same verified author to bypass manual intervention.\nOnce the payload is stored and rendered, the JavaScript executes within the session of the unsuspecting visitor.\nThis execution environment allows for the exfiltration of cookies (if not protected by HttpOnly flags), the modification of Document Object Model (DOM) elements on the page, or the redirection of the user to malicious external domains.\nBecause the payload is stored server-side in the database, it remains persistent, ensuring that every page load containing the malicious comment executes the script anew, maximizing the impact to every visitor of the compromised page.\nThe vulnerability is present in all versions up to and including 4.5.1, and there is currently no evidence of robust sanitization routines within the affected component's processing function to handle non-compliant or malicious attribute definitions."
}
CVE-2026-96682: Presto Player Stored XSS Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere