Sceawere

Vulnerability Detail

CVE-2026-97336UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CMB2 Stored Cross-Site Scripting

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
jtsternberg
Product
CMB2
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integrating plugin or theme registers a file_list field on a publicly accessible front-end form or a user meta box, as CMB2 is a developer library and does not expose these fields by default.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:04.983Z",
  "pubdate": "2026-10-02T08:17:04.983Z",
  "executiveSummary": "The CMB2 plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.13.0.\nThe vulnerability originates from inadequate input sanitization and output escaping within the 'file_list' field type component.\nThis flaw allows unauthenticated attackers to inject malicious JavaScript payloads into affected front-end forms or user meta boxes where CMB2 fields are implemented.\nWhen a user or administrator accesses a page containing the injected content, the malicious script executes within the context of their session.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of the victim, and data exfiltration.\nExploitation is conditional on the integration of a 'file_list' field within a publicly accessible front-end form or meta box, as CMB2 functions as a developer-centric library rather than an end-user interface.\nThe risk is elevated due to the lack of required authentication for the injection vector, potentially allowing external actors to compromise privileged user sessions.",
  "technicalDetails": "The root cause of this vulnerability is improper handling of user-supplied data within the CMB2 'file_list' field type. Specifically, the library fails to sufficiently sanitize input before storage and neglects to perform context-aware output escaping when rendering the data.\nAs CMB2 is designed as a developer toolkit for creating metaboxes and custom fields, it relies on the implementer to define the integration. When an integrating theme or plugin exposes a 'file_list' field on a front-end form or a public-facing user profile meta box, the lack of internal security controls within the library becomes an entry point for malicious input.\nThe attack flow begins when an attacker identifies a publicly accessible input field utilizing the 'file_list' configuration. The attacker submits a specially crafted payload containing malicious JavaScript, typically encapsulated within HTML tags (e.g., <script> tags or event handlers like onerror). Because the 'file_list' component lacks adequate sanitization, the application stores this raw malicious string in the database.\nThe vulnerability is realized when the application retrieves and renders this data in a browser. Because the plugin does not properly escape the stored value during the output phase, the browser interprets the injected JavaScript as legitimate code rather than inert text. Consequently, the payload executes automatically whenever a user, including site administrators, views the injected page.\nSince the script executes in the context of the victim's browser, the payload can perform any action permitted by the victim's privileges. This includes reading sensitive data, modifying page content, or sending unauthorized requests to administrative endpoints via CSRF, provided the victim has an active session. The lack of authentication for the initial injection renders this a high-impact vector, as it does not require prior knowledge of legitimate user credentials or administrative access to initiate the stored payload.\nThis vulnerability is present in all versions through 2.13.0. The susceptibility of any given site is strictly dependent on whether the developer has exposed the 'file_list' field type to public interaction through theme or plugin logic."
}
CVE-2026-97336: CMB2 Stored Cross-Site Scripting (HIGH Severity, CVSS: 7.2) | Sceawere