Description
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have configured a text-type custom user attribute whose display format places %value% inside an HTML attribute context (e.g., the documented pattern &lt;a href="%value%"&gt;Custom link&lt;/a&gt;), and for front-end user profiles to be enabled — both of which reflect the plugin's standard, documented configuration.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The HivePress plugin for WordPress contains a stored XSS flaw that allows an unauthenticated attacker to embed malicious scripts in custom user attribute values submitted via the registration form. The plugin fails to sanitize or escape the input before outputting it inside an HTML attribute context, so the injected JavaScript runs whenever a page displaying the affected profile is viewed. This is a classic stored cross‑site scripting vulnerability, classified as CWE‑79, and enables attackers to execute code in the browsers of any users who view the compromised profile page, potentially leading to credential theft, session hijacking, or defacement.

Affected Systems

The vulnerability affects all releases of the HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress up to and including version 1.7.31. An administrator must have enabled the text‑type custom user attribute with a display format that places the raw user input inside an HTML attribute context (e.g., a link’s href), and front‑end user profiles must be enabled. Only version 1.7.32 and newer contain the fix.

Risk and Exploitability

The CVSS score of 7.2 indicates a moderate‑to‑high severity level. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits have yet been observed. The attack requires an unauthenticated attacker to register a new user with a malicious custom attribute payload, and an administrator with the appropriate attribute configuration. Once injected, the script will execute in every user’s browser that accesses the compromised profile page, allowing an attacker to hijack sessions, steal credentials, or deface the site.

Generated by OpenCVE AI on October 10, 2026 at 09:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the HivePress plugin to version 1.7.32 or later, which removes the input sanitization flaw.
  • If an upgrade is not immediately possible, disable front‑end user profile viewing or remove the custom user attribute that puts user input inside an HTML attribute context.
  • Sanitize or clear any existing custom attribute values that may contain injected content, and ensure the display format is plain text before re‑enabling front‑end profiles.

Generated by OpenCVE AI on October 10, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have configured a text-type custom user attribute whose display format places %value% inside an HTML attribute context (e.g., the documented pattern &lt;a href="%value%"&gt;Custom link&lt;/a&gt;), and for front-end user profiles to be enabled — both of which reflect the plugin's standard, documented configuration.
Title HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribute Value via Registration Form
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T08:26:40.211Z

Reserved: 2026-10-08T14:36:30.619Z

Link: CVE-2026-107657

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T09:16:38.940

Modified: 2026-10-10T09:16:38.940

Link: CVE-2026-107657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T10:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')