<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:dofollow_case_by_case:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpressdofollow_case_by_case/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:24:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpressdofollow_case_by_case/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in DoFollow Case by Case WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-dofollow-xss/</link><pubDate>Fri, 02 Oct 2026 08:24:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-dofollow-xss/</guid><description>The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts in the browsers of site visitors.</description><content:encoded><![CDATA[<p>The DoFollow Case by Case plugin for WordPress (all versions up to and including 3.6.0) contains a vulnerability that permits Stored Cross-Site Scripting (XSS). This flaw stems from the plugin's failure to properly sanitize and escape content submitted via comment fields. Because the input is not validated, an unauthenticated attacker can embed malicious JavaScript payloads within a comment submission.</p>
<p>While standard WordPress comment moderation settings may delay the delivery of the exploit, once an administrator approves a comment containing a payload, the script is rendered on the post page. Subsequently, the script executes within the context of any user's browser who views the affected post, including site administrators. This vulnerability poses a significant risk to the integrity of the WordPress site by enabling session hijacking, account takeover, or unauthorized administrative actions. Defenders should treat this as a high-priority risk if the plugin cannot be immediately updated or removed.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of site visitors, including high-privileged administrators. This can lead to the theft of session cookies, the creation of rogue administrator accounts, or unauthorized content modification, effectively compromising the WordPress site and its user base.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the DoFollow Case by Case plugin to a patched version beyond 3.6.0 immediately.</li>
<li>Disable the comment feature on public-facing posts until the patch is verified and applied.</li>
<li>Monitor web server logs for suspicious HTTP POST requests directed at comment submission endpoints (<code>/wp-comments-post.php</code>) containing script tags or common XSS vectors.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>wordpress</category></item></channel></rss>