
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-107657 is a Stored Cross-Site Scripting (XSS) vulnerability in the HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress, affecting all versions up to and including 1.7.31. The flaw arises from insufficient input sanitization and output escaping of custom user attribute fields, allowing unauthenticated attackers to inject persistent malicious JavaScript into pages viewed by other users. It was published on October 10, 2026, with a patch released in version 1.7.32. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and stems from the plugin's failure to properly sanitize or escape user-supplied values when rendering custom user attributes on front-end profile pages. Specifically, when an administrator configures a text-type custom user attribute with a display format that places %value% inside an HTML attribute context (e.g., <a href="%value%">Custom link</a>), attacker-controlled input is rendered unescaped into the HTML output. The vulnerable code paths are identifiable in class-attribute.php (line 1298), class-field.php (line 561), class-text.php (line 197), and helpers.php (line 382) of the 1.7.31 release. Exploitation requires no authentication, no privileges, and no user interaction, but does require two administrator-configured preconditions: a text-type custom attribute with an HTML attribute context display format, and front-end user profiles being enabled — both of which are standard, documented plugin configurations (GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of any user who visits a profile page containing the injected content. This can result in session cookie theft, credential harvesting, user redirection to malicious sites, content defacement, or performing unauthorized actions on behalf of authenticated users (including administrators). The scope is changed (S:C in CVSS), meaning the injected script can affect resources beyond the vulnerable component itself (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is network-exploitable with no authentication or user interaction required, lowering the barrier for exploitation once the specific administrator-configured preconditions are met. No threat actor attribution has been reported, and the CVE does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
%value% inside an HTML attribute context (e.g., <a href="%value%">Custom link</a>).javascript:alert(document.cookie) or " onmouseover="alert(1) that breaks out of the HTML attribute context and injects executable JavaScript.<script>, javascript:, onerror=, onmouseover=).wp_usermeta table associated with HivePress custom attribute meta keys (e.g., profile_test or similar custom field names).The primary remediation is to update the HivePress plugin to version 1.7.32 or later, which addresses the insufficient sanitization and output escaping (GitHub Advisory, HivePress Release). If an immediate update is not possible, administrators should disable front-end user profiles or remove any text-type custom user attributes whose display format places %value% inside an HTML attribute context. Additionally, a Web Application Firewall (WAF) rule targeting XSS payloads in profile submission endpoints can provide interim protection.
The vulnerability was reported to the GitHub Advisory Database and Wordfence Threat Intelligence on October 10, 2026, with Wordfence tracking it under their vulnerability database (GitHub Advisory). No notable public researcher commentary, social media discussion, or broader media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."