Vulnerability DatabaseCVE-2026-107657

CVE-2026-107657: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-107657 is a Stored Cross-Site Scripting (XSS) vulnerability in the HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress, affecting all versions up to and including 1.7.31. The flaw arises from insufficient input sanitization and output escaping of custom user attribute fields, allowing unauthenticated attackers to inject persistent malicious JavaScript into pages viewed by other users. It was published on October 10, 2026, with a patch released in version 1.7.32. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and stems from the plugin's failure to properly sanitize or escape user-supplied values when rendering custom user attributes on front-end profile pages. Specifically, when an administrator configures a text-type custom user attribute with a display format that places %value% inside an HTML attribute context (e.g., <a href="%value%">Custom link</a>), attacker-controlled input is rendered unescaped into the HTML output. The vulnerable code paths are identifiable in class-attribute.php (line 1298), class-field.php (line 561), class-text.php (line 197), and helpers.php (line 382) of the 1.7.31 release. Exploitation requires no authentication, no privileges, and no user interaction, but does require two administrator-configured preconditions: a text-type custom attribute with an HTML attribute context display format, and front-end user profiles being enabled — both of which are standard, documented plugin configurations (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of any user who visits a profile page containing the injected content. This can result in session cookie theft, credential harvesting, user redirection to malicious sites, content defacement, or performing unauthorized actions on behalf of authenticated users (including administrators). The scope is changed (S:C in CVSS), meaning the injected script can affect resources beyond the vulnerable component itself (GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is network-exploitable with no authentication or user interaction required, lowering the barrier for exploitation once the specific administrator-configured preconditions are met. No threat actor attribution has been reported, and the CVE does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running HivePress plugin version ≤ 1.7.31 with front-end user profiles enabled (e.g., by checking plugin version in page source or using tools like WPScan).
  2. Verify preconditions: Confirm that the target site has a text-type custom user attribute configured with a display format placing %value% inside an HTML attribute context (e.g., <a href="%value%">Custom link</a>).
  3. Register or access a user profile: Navigate to the front-end user registration or profile editing page exposed by the HivePress plugin.
  4. Inject malicious payload: In the custom user attribute field (e.g., a profile URL field), submit a crafted XSS payload such as javascript:alert(document.cookie) or " onmouseover="alert(1) that breaks out of the HTML attribute context and injects executable JavaScript.
  5. Persist and trigger: The malicious value is stored in the database. When any user (including administrators) visits the attacker's profile page, the injected script executes in their browser, enabling cookie theft, session hijacking, or further malicious actions (GitHub Advisory).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to front-end user profile or registration endpoints with unusual payloads in custom attribute fields (e.g., values containing <script>, javascript:, onerror=, onmouseover=).
  • Database: Unexpected JavaScript or HTML event handler strings stored in the wp_usermeta table associated with HivePress custom attribute meta keys (e.g., profile_test or similar custom field names).
  • Network: Outbound requests from victim browsers to attacker-controlled domains (e.g., for cookie exfiltration) originating after visiting HivePress user profile pages.
  • Browser/Client: Unexpected redirects or pop-ups when visiting HivePress front-end profile pages; JavaScript errors in browser console referencing HivePress profile rendering.

Mitigation and workarounds

The primary remediation is to update the HivePress plugin to version 1.7.32 or later, which addresses the insufficient sanitization and output escaping (GitHub Advisory, HivePress Release). If an immediate update is not possible, administrators should disable front-end user profiles or remove any text-type custom user attributes whose display format places %value% inside an HTML attribute context. Additionally, a Web Application Firewall (WAF) rule targeting XSS payloads in profile submission endpoints can provide interim protection.

Community reactions

The vulnerability was reported to the GitHub Advisory Database and Wordfence Threat Intelligence on October 10, 2026, with Wordfence tracking it under their vulnerability database (GitHub Advisory). No notable public researcher commentary, social media discussion, or broader media coverage has been identified at this time.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91136HIGH7.5
  • divi-plus
NoYesOct 10, 2026
CVE-2026-107657HIGH7.2
  • hivepress
NoYesOct 10, 2026
CVE-2026-89269MEDIUM6.8
  • testimonial-widgets
NoNoOct 10, 2026
CVE-2026-4791MEDIUM6.4
  • peprodev-ups
NoYesOct 10, 2026
CVE-2026-89271MEDIUM5.3
  • wp-businessdirectory
NoNoOct 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management