Sceawere
Vulnerability Detail
CVE-2026-97396UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Retainful Plugin
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- retainful
- Product
- Email Marketing for WordPress and WooCommerce – Retainful
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Email Marketing for WordPress and WooCommerce – Retainful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T08:17:08.440Z",
"pubdate": "2026-10-10T08:17:08.440Z",
"executiveSummary": "The Email Marketing for WordPress and WooCommerce – Retainful plugin, in all versions up to and including 1.0.10, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw stems from inadequate sanitization of user-supplied input within the 'data' parameter.\nThe vulnerability permits authenticated attackers, possessing at least subscriber-level privileges, to inject and persist malicious JavaScript payloads within the application's database. When an unsuspecting user—such as an administrator—navigates to an affected page where the injected script is rendered, the payload executes within the context of the victim's session.\nThe impact of this vulnerability is significant, as it enables attackers to perform unauthorized actions on behalf of the victim, access sensitive data, or hijack user sessions. Given that the exploit requires only low-level subscriber authentication, the risk to the WordPress environment is elevated, potentially leading to a complete compromise of site integrity if a privileged user is targeted.",
"technicalDetails": "The root cause of this vulnerability is improper handling of user-supplied data within the plugin's internal processing logic. Specifically, the 'data' parameter fails to undergo rigorous input sanitization and context-aware output encoding before being stored in the WordPress database and subsequently rendered to the browser.\nThe vulnerability manifests because the plugin does not enforce strict character filtering or use appropriate WordPress escaping functions (e.g., esc_html(), esc_js(), or wp_kses()) on the content passed through the 'data' parameter. Consequently, an attacker can submit crafted input containing malicious scripts—such as <script>alert(document.cookie)</script>—which are then treated as legitimate data and persisted in the database.\nExploitation follows a predictable sequence: First, an authenticated attacker with subscriber-level permissions or higher sends a crafted HTTP request to the vulnerable endpoint, supplying a malicious payload within the 'data' parameter. The server-side application processes this input without adequate validation and saves the payload into the database. Subsequently, whenever an authorized user or administrator navigates to the administrative or front-end page where this stored data is dynamically retrieved and displayed, the server reflects the payload into the Document Object Model (DOM) without proper output encoding.\nWhen the victim's browser parses the malicious HTML/JS injected by the attacker, it treats the script as an integral part of the document and executes it with the permissions of the authenticated victim. Because the execution occurs within the browser environment, the injected script can access session cookies, perform background AJAX requests to the WordPress API to escalate privileges, or modify the site's content via administrative interfaces.\nThis Stored XSS vulnerability is particularly dangerous because the malicious content is persistent. It does not require continuous attacker activity to function; the payload will trigger for any user who views the page containing the injected script. The scope of the attack is limited only by the attacker's ability to inject scripts that interact with the available DOM elements and the security headers implemented on the target WordPress installation."
}