{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dofollow-case-by-case--3.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:dofollow_case_by_case:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-95817"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DoFollow Case by Case (\u003c= 3.6.0)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe DoFollow Case by Case plugin for WordPress (all versions up to and including 3.6.0) contains a vulnerability that permits Stored Cross-Site Scripting (XSS). This flaw stems from the plugin's failure to properly sanitize and escape content submitted via comment fields. Because the input is not validated, an unauthenticated attacker can embed malicious JavaScript payloads within a comment submission.\u003c/p\u003e\n\u003cp\u003eWhile standard WordPress comment moderation settings may delay the delivery of the exploit, once an administrator approves a comment containing a payload, the script is rendered on the post page. Subsequently, the script executes within the context of any user's browser who views the affected post, including site administrators. This vulnerability poses a significant risk to the integrity of the WordPress site by enabling session hijacking, account takeover, or unauthorized administrative actions. Defenders should treat this as a high-priority risk if the plugin cannot be immediately updated or removed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browsers of site visitors, including high-privileged administrators. This can lead to the theft of session cookies, the creation of rogue administrator accounts, or unauthorized content modification, effectively compromising the WordPress site and its user base.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the DoFollow Case by Case plugin to a patched version beyond 3.6.0 immediately.\u003c/li\u003e\n\u003cli\u003eDisable the comment feature on public-facing posts until the patch is verified and applied.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious HTTP POST requests directed at comment submission endpoints (\u003ccode\u003e/wp-comments-post.php\u003c/code\u003e) containing script tags or common XSS vectors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T08:24:01Z","date_published":"2026-10-02T08:24:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-dofollow-xss/","summary":"The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization, allowing unauthenticated attackers to execute arbitrary scripts in the browsers of site visitors.","title":"Stored XSS in DoFollow Case by Case WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-dofollow-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - DoFollow Case by Case (\u003c= 3.6.0)","version":"https://jsonfeed.org/version/1.1"}