<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP-Lister - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/wp-lister/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 05:46:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/wp-lister/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in WP-Lister Lite for eBay WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-wp-lister-xss/</link><pubDate>Wed, 16 Sep 2026 05:46:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wp-lister-xss/</guid><description>The WP-Lister Lite for eBay plugin for WordPress contains a Stored Cross-Site Scripting vulnerability in its AJAX Cron Handler allowing unauthenticated script injection.</description><content:encoded><![CDATA[<p>The WP-Lister Lite for eBay plugin for WordPress, in versions up to and including 3.8.9, is affected by a Stored Cross-Site Scripting (XSS) vulnerability. The flaw resides in the AJAX Cron Handler, which fails to perform adequate input sanitization and output escaping on request parameters. This vulnerability allows an unauthenticated attacker to inject malicious JavaScript into the plugin settings or associated pages. When an administrative user or other authenticated user views the compromised page, the attacker-supplied script executes within the context of the victim's browser session. This can lead to unauthorized actions, session hijacking, or the defacement of the affected WordPress site. Defenders should monitor web logs for anomalous POST requests directed at the plugin's AJAX endpoints and ensure all plugins are updated to the latest version.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of users accessing the affected site. This could result in unauthorized administrative actions, the theft of session cookies, or further compromise of the WordPress environment. The vulnerability impacts all users of WP-Lister Lite for eBay running versions 3.8.9 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the WP-Lister Lite for eBay plugin to the latest version immediately to remediate CVE-2026-18595. In environments where patching is delayed, monitor server access logs for suspicious input patterns within requests targeting plugin AJAX endpoints.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>