Description
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an administrator has configured a Text attribute whose display format places the %value% token inside an HTML attribute (e.g., title="%value%"), which is a documented HivePress pattern.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross-Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The HivePress plugin is vulnerable to stored cross‑site scripting when an administrator configures a custom text attribute so that its display format places the %value% token inside an HTML attribute, such as title="%value%". Authenticated users at the subscriber level or higher can submit any value for that field. Because the plugin does not sanitise or escape the input, the value is stored and later rendered into an HTML attribute, allowing an attacker to inject arbitrary JavaScript that executes in the browsers of any user viewing the affected listing page. The flaw corresponds to CWE‑79 and can lead to code execution, session hijacking, defacement, and data theft.

Affected Systems

HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress, all releases up to and including version 1.7.31. The issue is fixed in release 1.7.32 and later.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, so active exploitation data is unknown. However, the attack requires only subscriber‑level access and the presence of a vulnerable attribute configuration, both common in WordPress environments. An attacker can easily create a subscriber account, supply a malicious payload in a custom attribute, and then cause the payload to execute whenever another user visits the associated listing. The combination of moderate severity and realistic exploitation conditions means this vulnerability should be treated as high priority and addressed promptly.

Generated by OpenCVE AI on October 10, 2026 at 06:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HivePress to version 1.7.32 or later to apply the vendor fix.
  • Review and adjust any custom attribute definitions that place the %value% token inside an HTML attribute; either remove the attribute or change the format to a safe plain‑text context and ensure proper escaping.
  • If an upgrade cannot be performed immediately, restrict subscriber‑level users from editing custom attributes or temporarily disable custom attribute editing for that role.

Generated by OpenCVE AI on October 10, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an administrator has configured a Text attribute whose display format places the %value% token inside an HTML attribute (e.g., title="%value%"), which is a documented HivePress pattern.
Title HivePress <= 1.7.31 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Listing Attribute Value in Administrator-configured HTML Format
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:30:59.972Z

Reserved: 2026-09-30T19:01:59.662Z

Link: CVE-2026-103520

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:38.290

Modified: 2026-10-10T06:16:38.290

Link: CVE-2026-103520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')