Skip to content
Threat Feed
high advisory

Stored XSS in HivePress WordPress Plugin

The HivePress WordPress plugin for versions 1.7.31 and below contains a stored Cross-Site Scripting (XSS) vulnerability that allows unauthenticated attackers to execute arbitrary scripts in the context of user profiles.

CVE search metadata

CVE search record: CVE-2026-107657. Severity: high. CVSS: 7.2. KEV: no. Product: HivePress (<= 1.7.31). Brief: Stored XSS in HivePress WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hivepress-xss/

The HivePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 1.7.31. The vulnerability exists due to insufficient input sanitization and output escaping of custom user attribute fields. An unauthenticated attacker can exploit this flaw if an administrator has configured a text-type custom user attribute using a display format that places the %value% variable inside an HTML attribute context, such as an 'href' attribute in an anchor tag. When front-end user profiles are enabled, the attacker can submit malicious JavaScript payloads into these fields. Once saved, these scripts execute in the browser of any user or administrator who views the injected user profile page. This can lead to unauthorized actions, session hijacking, or redirection, depending on the victim's privileges.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the session of a victim viewing a profile page. This can result in session token theft, the performance of actions on behalf of the victim (including administrative actions if the victim is an administrator), and account takeover, significantly impacting the integrity and confidentiality of the affected WordPress site.

Recommendation

Update the HivePress plugin to a version released after 1.7.31 immediately. If an update is not immediately available, disable front-end user profile displays or remove custom user attributes that are configured with the %value% variable inside HTML attributes until a patch is applied.

Mitigations

Upgrade HivePress plugin to the latest version, which contains a fix for CVE-2026-107657

immediate IT Operations

CVE-2026-107657