<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-96813 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-96813/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:40:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-96813/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Form Maker by 10Web WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96813/</link><pubDate>Thu, 01 Oct 2026 10:40:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96813/</guid><description>The Form Maker by 10Web WordPress plugin contains a stored cross-site scripting vulnerability in longitude and latitude fields that allows unauthenticated attackers to execute arbitrary scripts in the context of other users.</description><content:encoded><![CDATA[<p>The Form Maker by 10Web plugin for WordPress (versions 1.15.47 and below) is affected by a stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-96813. The vulnerability exists within the Mark on Map feature, specifically due to insufficient input sanitization and output escaping on the longitude and latitude fields. An unauthenticated attacker can submit malicious payloads through these parameters, which are subsequently stored by the application. When a victim, such as an administrator or other user, views the page where this content is rendered, the script executes in their browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or redirection to malicious sites. Defenders should prioritize updating to a version beyond 1.15.47 once a patch is available and monitor web application logs for suspicious input containing script tags or event handlers.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to WordPress sites utilizing the Form Maker plugin. Successful exploitation allows unauthenticated attackers to execute malicious JavaScript, potentially compromising user accounts, bypassing security controls, or defacing site content. Since the vulnerability is stored, a single successful injection can impact every user who accesses the compromised page, creating a persistent threat until the malicious data is removed and the plugin is updated.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Form Maker by 10Web plugin to the latest version (above 1.15.47) immediately to resolve the lack of input sanitization.</li>
<li>Implement a Web Application Firewall (WAF) rule to inspect input parameters related to the Mark on Map feature for suspicious script injection patterns (e.g., &lt;script&gt;, onerror, onload).</li>
<li>Review WordPress logs for unusual POST requests targeting form submission or map configuration endpoints that contain non-numeric characters in coordinates.</li>
<li>Apply the principle of least privilege for WordPress administrative access to minimize the impact of potential session hijacking resulting from successful XSS exploitation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-96813</category></item></channel></rss>