{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/plugin-security/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-15002"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Platnosci Online Blue Media (Autopay) plugin"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress","plugin-security"],"_cs_type":"advisory","_cs_vendors":["Autopay"],"content_html":"\u003cp\u003eThe Platnosci Online Blue Media (Autopay) plugin for WordPress (versions 5.0.0 and below) contains a critical stored Cross-Site Scripting (XSS) vulnerability. The flaw originates in the Css_Editor::handle_save() method, which is improperly registered to the WordPress 'init' hook via Settings_Manager::init_once(). This method fails to implement necessary capability checks, nonce verification, or input sanitization on the 'bm_woocommerce_css_editor_content' POST parameter. Consequently, the plugin stores raw user-provided input directly into the 'woocommerce_bluemedia_settings' database option.\u003c/p\u003e\n\u003cp\u003eWhen a user visits the WooCommerce checkout page, the Css_Frontend::print_to_wp_head() function retrieves this stored value and echoes it directly into a \u0026lt;style\u0026gt; block without output escaping. An unauthenticated attacker can leverage this injection point to execute arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the site user. The scope of this threat is significant given the plugin's integration into the checkout process, which is a high-value target for attackers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code in the browser context of any user viewing the WooCommerce checkout page. This can lead to full site administrative compromise if a site administrator views the page, or the theft of customer session cookies and sensitive checkout information. The vulnerability affects all WordPress installations utilizing the Platnosci Online Blue Media plugin up to version 5.0.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Platnosci Online Blue Media (Autopay) plugin to the latest available version beyond 5.0.0 immediately.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to inspect HTTP POST requests for the 'bm_woocommerce_css_editor_content' parameter to detect script-like payloads (e.g., \u0026lt;script\u0026gt;, javascript:, or event handlers).\u003c/li\u003e\n\u003cli\u003eImplement access control list (ACL) restrictions at the web server level to limit access to the endpoints responsible for updating settings if the plugin functionality is not strictly required.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests targeting the WordPress site with the identified parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T06:24:44Z","date_published":"2026-08-16T06:24:44Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wordpress-xss/","summary":"An unauthenticated stored Cross-Site Scripting vulnerability in the Platnosci Online Blue Media WordPress plugin allows attackers to inject malicious scripts into the checkout page.","title":"Stored XSS Vulnerability in Platnosci Online Blue Media Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wordpress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Plugin-Security","version":"https://jsonfeed.org/version/1.1"}