Sceawere
Vulnerability Detail
CVE-2026-96819UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Subscriber XSS in oik Plugin
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- bobbingwide
- Product
- oik
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:31.310Z",
"pubdate": "2026-09-30T13:17:31.310Z",
"executiveSummary": "The oik WordPress plugin, in versions 4.15.4 and lower, is susceptible to a Cross-Site Scripting (XSS) vulnerability specifically affecting users with the Subscriber role.\nThis vulnerability is categorized as a Stored or Reflected XSS flaw that allows authenticated attackers to inject and execute arbitrary malicious JavaScript within the administrative or front-end browser context of other users.\nThe root cause involves insufficient input validation and output encoding of user-supplied data, which permits the injection of script tags.\nImpact is significant, as successful exploitation enables attackers to hijack user sessions, perform unauthorized actions on behalf of site administrators, redirect users to malicious domains, or exfiltrate sensitive data such as session cookies or CSRF tokens.\nThis vulnerability requires the attacker to hold at least a Subscriber-level account on the WordPress installation to perform the exploitation.\nThe risk is elevated due to the potential for privilege escalation and the compromise of higher-privileged user sessions, potentially leading to a full site compromise if administrative sessions are targeted.\nNo specific network-level bypass is required, as the attack is delivered via the application's legitimate input vectors.",
"technicalDetails": "The vulnerability resides within the oik plugin's input handling routines, where user-provided parameters are inadequately sanitized before being rendered in the Document Object Model (DOM).\nIn versions up to 4.15.4, the plugin fails to implement sufficient contextual output encoding for parameters processed by its shortcode or administrative interface functions. This allows an authenticated attacker with Subscriber privileges to supply crafted payloads—typically JavaScript encapsulated within HTML tags—that the application stores or reflects back to other users.\nThe attack flow begins with the attacker crafting an HTTP request containing a malicious payload designed to escape the intended data container. Because the oik plugin processes these inputs without proper escaping, the payload is rendered by the victim's browser as executable code rather than plain text.\nWhen an administrator or another user views the page or administrative panel where the injected payload resides, the browser interprets the script tags. Due to the lack of Content Security Policy (CSP) headers or adequate input filtering, the script executes within the security context of the victim's current session.\nThe execution of this JavaScript allows the attacker to gain programmatic access to the victim's browser environment. This enables the theft of authentication cookies, the modification of page content to present fraudulent login prompts, or the execution of unauthorized administrative actions, such as creating new user accounts or installing malicious plugins, leveraging the victim's authenticated session.\nThe vulnerability is primarily triggered by the failure to utilize standard WordPress security APIs such as esc_html(), esc_attr(), or wp_kses() when handling user input. This oversight creates a trust boundary violation where untrusted data is treated as trusted content. The exploitation is persistent if the payload is stored in the database, meaning the script will execute every time the affected page is loaded, or transient if it relies on reflected input parameters.\nThe scope of the impact is localized to the site where the plugin is active, but the privilege escalation potential through session manipulation makes this a critical security concern for WordPress environments utilizing oik for dynamic content generation."
}