{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apresto_playerpresto_player/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:presto_player:presto_player:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96682"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Presto Player (\u003c= 4.5.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-96682"],"_cs_type":"advisory","_cs_vendors":["Presto Player"],"content_html":"\u003cp\u003eThe Presto Player plugin for WordPress (versions up to and including 4.5.1) contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw stems from insufficient input sanitization and output escaping when processing content within the \u0026lt;presto-player\u0026gt; tag. An unauthenticated attacker can inject arbitrary malicious scripts into comment fields. While the initial injection may require comment approval, WordPress default settings often auto-approve subsequent comments from the same author, providing an attacker with a mechanism to persist and execute payloads without further administrative intervention. Impact includes unauthorized script execution within the context of a victim's session, potentially leading to session hijacking, defacement, or redirection to malicious sites.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site with Presto Player plugin version 4.5.1 or earlier installed.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious comment containing a crafted \u0026lt;presto-player\u0026gt; tag with embedded JavaScript.\u003c/li\u003e\n\u003cli\u003eAttacker submits the comment via the public comment form.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the site's default auto-approval configuration or waits for manual administrator approval of the comment.\u003c/li\u003e\n\u003cli\u003eThe malicious script is stored in the WordPress database linked to the comment content.\u003c/li\u003e\n\u003cli\u003eVictim visits the page where the comment is rendered.\u003c/li\u003e\n\u003cli\u003eThe browser renders the \u0026lt;presto-player\u0026gt; tag, triggering the execution of the injected script in the context of the victim's session.\u003c/li\u003e\n\u003cli\u003eAttacker achieves malicious script execution (e.g., session token theft).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary scripts in the browsers of site visitors, including administrators. This can lead to account takeover, unauthorized actions performed on behalf of authenticated users, and theft of sensitive session information. The vulnerability affects all users running vulnerable versions of the Presto Player plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Presto Player plugin to the latest available version beyond 4.5.1 to remediate CVE-2026-96682. Implement a Web Application Firewall (WAF) to detect and block malicious script injection attempts targeting the \u0026lt;presto-player\u0026gt; tag in comment inputs. Review WordPress comment moderation settings to require manual approval for all new user comments to mitigate auto-approval exploitation vectors.\u003c/p\u003e\n","date_modified":"2026-10-10T07:51:59Z","date_published":"2026-10-10T07:51:59Z","id":"https://feed.craftedsignal.io/briefs/2026-10-presto-player-xss/","summary":"The Presto Player WordPress plugin is vulnerable to Stored Cross-Site Scripting via the presto-player tag, allowing unauthenticated attackers to execute arbitrary web scripts.","title":"Stored XSS in Presto Player WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-presto-player-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:presto_player:presto_player:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}