<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-96567 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-96567/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 10:23:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-96567/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in MW WP Form WordPress Plugin via post_id Parameter</title><link>https://feed.craftedsignal.io/briefs/2026-10-mw-wp-form-xss/</link><pubDate>Fri, 02 Oct 2026 10:23:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mw-wp-form-xss/</guid><description>The MW WP Form WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of the 'post_id' parameter, enabling unauthenticated attackers to bypass CSRF protections and execute arbitrary scripts in victim sessions.</description><content:encoded><![CDATA[<p>The MW WP Form plugin for WordPress, in versions 5.1.7 and earlier, contains a critical input sanitization vulnerability. Attackers can leverage this flaw to perform Stored Cross-Site Scripting (XSS) by manipulating the 'post_id' parameter during form processing. The vulnerability is compounded by an insecure CSRF protection mechanism (MW_WP_Form_Csrf), which relies on a double-submit cookie that can be acquired by any unauthenticated visitor who loads the public-facing form page. Because the plugin fails to properly sanitize input or escape output, malicious actors can inject arbitrary JavaScript payloads into the WordPress database. These payloads execute in the browsers of users - including administrators - who view the affected pages or form submissions, potentially leading to unauthorized actions, session hijacking, or site defacement. This issue highlights the danger of predictable or bypassable CSRF tokens when combined with inadequate input handling.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker loads a public webpage containing a form managed by the MW WP Form plugin.</li>
<li>The application serves the form and issues a double-submit CSRF cookie (MW_WP_Form_Csrf) to the browser.</li>
<li>The attacker retrieves the valid CSRF token/cookie pair from the initial page load.</li>
<li>The attacker crafts a malicious HTTP POST request targeting the form submission endpoint.</li>
<li>The attacker includes a cross-site scripting payload within the 'post_id' parameter.</li>
<li>The application accepts the POST request, validating the CSRF cookie, and saves the malicious 'post_id' to the underlying database without sanitization.</li>
<li>A victim user, such as an administrator, accesses the administrative interface or a page displaying the form submission data.</li>
<li>The stored JavaScript payload executes in the victim's browser context, enabling further malicious activity.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of any user who accesses the compromised form submission pages. This may result in total site compromise if an administrative account views the malicious payload, enabling account takeover, unauthorized creation of admin users, or malicious modifications to site content.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams:</p>
<ul>
<li>Immediately identify all WordPress instances running MW WP Form versions 5.1.7 or older.</li>
<li>Update the MW WP Form plugin to the latest secure version addressing CVE-2026-96567.</li>
<li>Implement a Web Application Firewall (WAF) rule to block POST requests containing suspicious characters (e.g., &lt;script&gt;, javascript:, onload=) in the 'post_id' parameter.</li>
<li>Monitor webserver access logs for anomalous POST requests to form submission endpoints originating from unknown or non-customer IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-96567</category></item></channel></rss>