Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

A stored cross‑site scripting (XSS) vulnerability exists in the Brainstorm Force Starter Templates WordPress plugin, allowing an attacker to inject malicious scripts that will be rendered when the web page is loaded. The flaw arises from improper neutralization of user input during web page generation, which is identified as CWE‑79. Successful exploitation could let an attacker run arbitrary JavaScript in the context of site visitors. Based on the description, it is inferred that such exploitation could compromise user sessions or deface content.

Affected Systems

The vulnerability applies to all versions of the Starter Templates plugin up to and including version 4.7.7 released by Brainstorm Force. Users who have not upgraded past this point remain exposed.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as medium severity, and the exploit probability score (EPSS) is not available, indicating that no public exploitation data is known at this time. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is web‑based and requires the attacker to insert malicious input that is stored by the plugin’s settings or content creator interface. An attacker with access to such input can later cause victim browsers to execute the injected script when the page is rendered.

Generated by OpenCVE AI on October 5, 2026 at 11:25 UTC.

Remediation

Vendor Solution

Update the WordPress Starter Templates plugin to the latest available version (at least 4.7.8).


OpenCVE Recommended Actions

  • Update the WordPress Starter Templates plugin to version 4.7.8 or newer.
  • Audit existing posts and widgets for injected scripts and remove any found.
  • Implement a web application firewall or enable XSS protection to block future attempts.

Generated by OpenCVE AI on October 5, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7.
Title WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T14:55:00.543Z

Reserved: 2026-09-29T00:15:56.342Z

Link: CVE-2026-102393

cve-icon Vulnrichment

Updated: 2026-10-05T14:50:21.555Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:05.850

Modified: 2026-10-05T15:17:14.287

Link: CVE-2026-102393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')