Description
The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by Settings_Manager::init_once() with no capability check, no nonce verification, and no sanitization on the input — the raw $_POST value is written to the 'woocommerce_bluemedia_settings' option via update_option(), then later echoed directly inside a <style> block on the WooCommerce checkout page by Css_Frontend::print_to_wp_head() with no output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (the checkout page).
Published: 2026-08-16
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Autopay plugin for WordPress is vulnerable to stored XSS in versions up to 5.0.0. The flaw arises from the Css_Editor::handle_save() method, which registers on the WordPress init hook without a capability check, nonce verification, or input sanitization. The raw user input is written directly to the woocommerce_bluemedia_settings option and later echoed inside a <style> tag on the checkout page with no escaping. This enables attackers to inject arbitrary JavaScript that will run when any user loads the checkout page.

Affected Systems

The vulnerability affects the Bluemedia Autopay plugin for WordPress, specifically versions 5.0.0 and earlier.

Risk and Exploitability

The CVSS score of 7.2 indicates a moderate to high risk, and the flaw is not listed in the CISA KEV catalog, with no EPSS data available. Because the attack vector requires no authentication, any external user can submit the malicious bm_woocommerce_css_editor_content POST parameter and persist the payload. Once stored, the script executes for every user visiting the compromised checkout page, potentially leading to session hijacking, defacement, or malicious redirection.

Generated by OpenCVE AI on August 16, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Autopay plugin to the latest version in which the XSS flaw has been corrected.
  • If an upgrade is not immediately possible, temporarily disable or uninstall the Autopay plugin to remove the vulnerable input handler.
  • As a supplemental measure, implement input sanitization for the bm_woocommerce_css_editor_content parameter and escape the output before it is rendered within the <style> block.

Generated by OpenCVE AI on August 16, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by Settings_Manager::init_once() with no capability check, no nonce verification, and no sanitization on the input — the raw $_POST value is written to the 'woocommerce_bluemedia_settings' option via update_option(), then later echoed directly inside a <style> block on the WooCommerce checkout page by Css_Frontend::print_to_wp_head() with no output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (the checkout page).
Title Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-16T04:24:56.453Z

Reserved: 2026-07-07T20:03:20.798Z

Link: CVE-2026-15002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T05:16:46.620

Modified: 2026-08-16T05:16:46.620

Link: CVE-2026-15002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T05:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')