{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressmagic_tooltips_for_contact_form_7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:magic_tooltips_for_contact_form_7:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-101928"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Magic Tooltips For Contact Form 7 (\u003c= 1.0.34)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Magic Tooltips For Contact Form 7 plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-101928) impacting all versions up to and including 1.0.34. The flaw stems from insufficient input sanitization and improper output escaping within the plugin's comment handling logic. Specifically, the plugin employs an 'esc_html' filter callback that inadvertently decodes HTML-entity-encoded payloads back into live HTML.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can supply a malicious script payload, encoded as HTML entities, within the 'author' parameter of a comment submission. This payload bypasses the standard 'sanitize_text_field' protections. Once stored, the script executes in the context of an administrator's browser when they access the 'wp-admin/edit-comments.php' page. This represents a significant risk for privilege escalation via session hijacking or administrative action manipulation within the WordPress dashboard.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This may lead to account takeover, unauthorized administrative actions, or the deployment of further malicious content within the site, potentially compromising all users and data managed by the affected WordPress instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Magic Tooltips For Contact Form 7 plugin to a version later than 1.0.34, or disable the plugin until a patch is applied.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for POST requests to comment submission endpoints containing HTML entity-encoded patterns or suspicious script tags.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block POST requests containing common XSS vectors in comment form parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T06:53:55Z","date_published":"2026-10-03T06:53:55Z","id":"https://feed.craftedsignal.io/briefs/2026-10-xss-magic-tooltips/","summary":"An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Magic Tooltips For Contact Form 7 plugin up to version 1.0.34 allows attackers to inject malicious scripts via the author parameter.","title":"Stored XSS in Magic Tooltips For Contact Form 7 Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-xss-magic-tooltips/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:magic_tooltips_for_contact_form_7:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}