{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azero_spam_for_wordpresszero_spam_for_wordpresswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zero_spam_for_wordpress:zero_spam_for_wordpress:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96752"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zero Spam for WordPress (\u003c= 5.7.10)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-96752"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Zero Spam for WordPress plugin, versions 5.7.10 and earlier, contains a critical Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-96752. The issue stems from insufficient input sanitization and output escaping when processing data submitted via Contact Form 7. An unauthenticated attacker can exploit this by submitting a request containing a crafted nested POST array key. If the plugin's security features flag the submission as spam, the malicious payload is stored verbatim in the 'zerospam_log' database table within the 'submission_data' column. When an administrative user views the submission logs in the WordPress dashboard, the injected script executes in the context of the administrator's session. This vulnerability poses a significant risk, as it allows attackers to potentially hijack sessions, perform unauthorized administrative actions, or inject further malicious content into the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site utilizing both the Zero Spam for WordPress plugin and Contact Form 7.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the Contact Form 7 endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker embeds a malicious JavaScript payload within a nested POST array key (e.g., fieldname[subfield]=\u0026lt;script\u0026gt;alert(1)\u0026lt;/script\u0026gt;).\u003c/li\u003e\n\u003cli\u003eAttacker submits the form without the mandatory 'zerospam_david_walsh_key' field to ensure the request is flagged as spam.\u003c/li\u003e\n\u003cli\u003eThe Zero Spam plugin intercepts the request and saves the malicious input into the 'zerospam_log' database table.\u003c/li\u003e\n\u003cli\u003eA WordPress administrator accesses the Zero Spam plugin dashboard to review flagged spam submissions.\u003c/li\u003e\n\u003cli\u003eThe administrator's browser renders the logged submission data, triggering the execution of the injected JavaScript payload.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of a WordPress administrator. This can lead to full site compromise, session theft, unauthorized data access, or the creation of rogue administrative accounts, impacting any WordPress site where the affected plugin is configured to monitor Contact Form 7 submissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Zero Spam for WordPress plugin to a version released after 5.7.10 that addresses CVE-2026-96752.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block POST requests containing non-alphanumeric characters or script tags in nested array keys targeted at WordPress form endpoints.\u003c/li\u003e\n\u003cli\u003eReview administrative access logs and the Zero Spam submission log entries for suspicious script injections or unexpected outbound connections occurring after form submissions.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by auditing WordPress user accounts and ensuring administrative access is restricted to verified personnel only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T08:59:40Z","date_published":"2026-09-25T08:59:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zero-spam-xss/","summary":"An unauthenticated Stored Cross-Site Scripting vulnerability in Zero Spam for WordPress (CVE-2026-96752) allows attackers to inject malicious scripts into logs via nested POST array keys in Contact Form 7 submissions.","title":"Stored XSS in Zero Spam for WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-zero-spam-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zero_spam_for_wordpress:zero_spam_for_wordpress:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}