<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hivepress:hivepress:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahivepresshivepresswordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:52:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahivepresshivepresswordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in HivePress WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-hivepress-xss/</link><pubDate>Sat, 10 Oct 2026 09:52:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hivepress-xss/</guid><description>The HivePress WordPress plugin for versions 1.7.31 and below contains a stored Cross-Site Scripting (XSS) vulnerability that allows unauthenticated attackers to execute arbitrary scripts in the context of user profiles.</description><content:encoded><![CDATA[<p>The HivePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 1.7.31. The vulnerability exists due to insufficient input sanitization and output escaping of custom user attribute fields. An unauthenticated attacker can exploit this flaw if an administrator has configured a text-type custom user attribute using a display format that places the %value% variable inside an HTML attribute context, such as an 'href' attribute in an anchor tag. When front-end user profiles are enabled, the attacker can submit malicious JavaScript payloads into these fields. Once saved, these scripts execute in the browser of any user or administrator who views the injected user profile page. This can lead to unauthorized actions, session hijacking, or redirection, depending on the victim's privileges.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the session of a victim viewing a profile page. This can result in session token theft, the performance of actions on behalf of the victim (including administrative actions if the victim is an administrator), and account takeover, significantly impacting the integrity and confidentiality of the affected WordPress site.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the HivePress plugin to a version released after 1.7.31 immediately. If an update is not immediately available, disable front-end user profile displays or remove custom user attributes that are configured with the %value% variable inside HTML attributes until a patch is applied.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category></item></channel></rss>