Description
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
Published: 2026-09-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw in the WPMU DEV Branda White Labeling plugin versions up to 3.4.32. It is caused by improper sanitization of subscriber‑related input that the plugin outputs in the page. As a result, a malicious actor can embed arbitrary JavaScript that is executed in the context of any user who views the affected page, potentially exposing sensitive information or modifying the user experience. This flaw aligns with CWE‑79.

Affected Systems

Any WordPress installation that has the WPMU DEV Branda White Labeling plugin installed and running in a version 3.4.32 or earlier is affected. The flaw is present regardless of the WordPress site's configuration and affects the default subscriber role or any role that can view subscriber data rendered by the plugin.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high‑severity vulnerability. Exploitation requires an attacker to supply crafted input that the plugin fails to escape. Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, there is no evidence of a widely used exploit, but the high severity suggests that organizations should evaluate the risk. The likely attack vector is user‑controlled input that reaches the plugin’s rendering logic and is not sanitized before being sent to the browser.

Generated by OpenCVE AI on September 30, 2026 at 20:24 UTC.

Remediation

Vendor Solution

Update the WordPress Branda White Labeling plugin to the latest available version (at least 3.4.33).


OpenCVE Recommended Actions

  • Upgrade the Branda plugin to version 3.4.33 or later
  • If an immediate upgrade is not possible, disable or remove the plugin to stop rendering subscriber data until the fix is applied
  • Employ a Content Security Policy that blocks inline scripts and restricts script execution to trusted sources, reducing the impact of any remaining malicious payloads

Generated by OpenCVE AI on September 30, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
Title WordPress Branda plugin <= 3.4.32 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:55.112Z

Reserved: 2026-09-29T00:15:56.340Z

Link: CVE-2026-102376

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:16.574Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:14.197

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-102376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')