{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cmb2--2.13.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cmb2:cmb2:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-97336"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CMB2 (\u003c= 2.13.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe CMB2 plugin for WordPress, a popular developer toolkit, contains a Stored Cross-Site Scripting (XSS) vulnerability in the 'file_list' field type, tracked as CVE-2026-97336. The vulnerability stems from insufficient input sanitization and output escaping within the field's handling logic. Attackers can exploit this by injecting arbitrary web scripts into any publicly accessible front-end form or user meta box that leverages this specific CMB2 field type. Because CMB2 functions as a developer library rather than a standalone user-facing product, the actual exposure of this flaw is dependent on how third-party themes or plugins implement these fields. Successful exploitation allows for the execution of malicious scripts in the context of a victim's session, which may lead to unauthorized actions or credential theft. This issue affects all versions of the CMB2 plugin up to and including 2.13.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables unauthenticated attackers to perform Stored XSS, allowing for the execution of arbitrary JavaScript in the browser of any user viewing the affected page. This can result in session hijacking, unauthorized modification of site content, or the redirection of users to malicious external domains. The scope of impact is contingent upon the prevalence of publicly accessible forms or meta boxes built with the CMB2 library across the target WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the CMB2 plugin to the latest version beyond 2.13.0 to include necessary sanitization and escaping patches.\u003c/li\u003e\n\u003cli\u003eReview custom themes and plugins that utilize the CMB2 library to identify instances where 'file_list' fields are exposed in public-facing forms or front-end user meta boxes.\u003c/li\u003e\n\u003cli\u003eImplement and enforce a strict Content Security Policy (CSP) to mitigate the impact of potential XSS vulnerabilities by restricting script execution sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T10:23:39Z","date_published":"2026-10-02T10:23:39Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cmb2-xss/","summary":"The CMB2 plugin for WordPress (\u003c= 2.13.0) is vulnerable to Stored XSS via the file_list field type, allowing unauthenticated attackers to inject malicious scripts into public-facing forms or user meta boxes.","title":"Stored Cross-Site Scripting in CMB2 WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cmb2-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - CMB2 (\u003c= 2.13.0)","version":"https://jsonfeed.org/version/1.1"}