{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/independent-analytics--2.15.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-17506"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Independent Analytics (\u003c= 2.15.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Independent Analytics"],"content_html":"\u003cp\u003eThe Independent Analytics plugin for WordPress (versions 2.15.0 and earlier) contains a high-severity Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-17506. The vulnerability stems from improper sanitization logic within the plugin's reporting functionality. Specifically, the get_cell_content() function applies a urldecode() operation after the initial esc_url() sanitization. This sequence permits percent-encoded HTML tags to bypass URL validation filters. Once decoded, the raw markup is rendered within the plugin's admin reporting interface.\u003c/p\u003e\n\u003cp\u003eThe flaw is exacerbated by the plugin's public REST endpoint, /iawp/search, which accepts unauthenticated requests. An attacker can leverage this to inject malicious payloads into the 404 tracking parameter. Because wp_kses_post() filtering allows certain img elements and data-* attributes, malicious payloads can persist in the database. When an administrator or authenticated user views the 404 report page, the injected script executes in their browser, potentially leading to unauthorized actions or credential theft.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to inject persistent malicious scripts into the WordPress site's reporting dashboard. This primarily threatens administrative accounts viewing the 404 URL column within the Independent Analytics plugin. Impact includes potential session hijacking, unauthorized administrative actions, and redirection of site users, affecting any WordPress installation using the vulnerable versions of this plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Independent Analytics plugin to the latest version immediately to remediate CVE-2026-17506.\u003c/li\u003e\n\u003cli\u003eAudit access logs for anomalous POST requests directed at the /iawp/search endpoint.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect the 'not_found_url' parameter for percent-encoded HTML characters or suspicious JavaScript patterns.\u003c/li\u003e\n\u003cli\u003eRestrict access to WordPress administrative dashboards and sensitive REST API endpoints to trusted IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T15:20:48Z","date_published":"2026-08-05T15:20:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-17506-xss/","summary":"The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found_url' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of victim browsers.","title":"Stored Cross-Site Scripting in Independent Analytics Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-17506-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Independent Analytics (\u003c= 2.15.0)","version":"https://jsonfeed.org/version/1.1"}