Impact
The HivePress plugin for WordPress contains a stored XSS flaw that allows an unauthenticated attacker to embed malicious scripts in custom user attribute values submitted via the registration form. The plugin fails to sanitize or escape the input before outputting it inside an HTML attribute context, so the injected JavaScript runs whenever a page displaying the affected profile is viewed. This is a classic stored cross‑site scripting vulnerability, classified as CWE‑79, and enables attackers to execute code in the browsers of any users who view the compromised profile page, potentially leading to credential theft, session hijacking, or defacement.
Affected Systems
The vulnerability affects all releases of the HivePress – Business Directory, Listings & Classified Ads Plugin for WordPress up to and including version 1.7.31. An administrator must have enabled the text‑type custom user attribute with a display format that places the raw user input inside an HTML attribute context (e.g., a link’s href), and front‑end user profiles must be enabled. Only version 1.7.32 and newer contain the fix.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate‑to‑high severity level. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits have yet been observed. The attack requires an unauthenticated attacker to register a new user with a malicious custom attribute payload, and an administrator with the appropriate attribute configuration. Once injected, the script will execute in every user’s browser that accesses the compromised profile page, allowing an attacker to hijack sessions, steal credentials, or deface the site.
OpenCVE Enrichment