<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cmb2:cmb2:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acmb2cmb2wordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 10:23:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acmb2cmb2wordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in CMB2 WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cmb2-xss/</link><pubDate>Fri, 02 Oct 2026 10:23:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cmb2-xss/</guid><description>The CMB2 plugin for WordPress (&lt;= 2.13.0) is vulnerable to Stored XSS via the file_list field type, allowing unauthenticated attackers to inject malicious scripts into public-facing forms or user meta boxes.</description><content:encoded><![CDATA[<p>The CMB2 plugin for WordPress, a popular developer toolkit, contains a Stored Cross-Site Scripting (XSS) vulnerability in the 'file_list' field type, tracked as CVE-2026-97336. The vulnerability stems from insufficient input sanitization and output escaping within the field's handling logic. Attackers can exploit this by injecting arbitrary web scripts into any publicly accessible front-end form or user meta box that leverages this specific CMB2 field type. Because CMB2 functions as a developer library rather than a standalone user-facing product, the actual exposure of this flaw is dependent on how third-party themes or plugins implement these fields. Successful exploitation allows for the execution of malicious scripts in the context of a victim's session, which may lead to unauthorized actions or credential theft. This issue affects all versions of the CMB2 plugin up to and including 2.13.0.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables unauthenticated attackers to perform Stored XSS, allowing for the execution of arbitrary JavaScript in the browser of any user viewing the affected page. This can result in session hijacking, unauthorized modification of site content, or the redirection of users to malicious external domains. The scope of impact is contingent upon the prevalence of publicly accessible forms or meta boxes built with the CMB2 library across the target WordPress environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the CMB2 plugin to the latest version beyond 2.13.0 to include necessary sanitization and escaping patches.</li>
<li>Review custom themes and plugins that utilize the CMB2 library to identify instances where 'file_list' fields are exposed in public-facing forms or front-end user meta boxes.</li>
<li>Implement and enforce a strict Content Security Policy (CSP) to mitigate the impact of potential XSS vulnerabilities by restricting script execution sources.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>xss</category></item></channel></rss>