Overview
A stored Cross-Site Scripting vulnerability has been disclosed in HivePress – Business Directory, Listings & Classified Ads Plugin, a widely used WordPress plugin for building directory, listing, and classified-ad sites. Tracked as CVE-2026-107657 with a CVSS score of 7.2 (High), the flaw lets an unauthenticated attacker inject arbitrary JavaScript into a custom user-profile attribute that later renders unescaped in an HTML attribute context — meaning the payload executes against any visitor who views the affected profile page.
The issue affects all versions up to and including 1.7.31 and is fixed in 1.7.32. It was identified by Wordfence's threat intelligence team and publicly disclosed on 2026-10-10.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-107657 |
| Severity | High (CVSS 7.2) |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
| CWE | CWE-79 — Improper Neutralization of Input During Web Page Generation |
| Authentication | None required to exploit (admin configuration required to create the vulnerable condition) |
| Affected Versions | ≤ 1.7.31 |
| Fixed Version | 1.7.32 |
How It Works
HivePress lets site administrators define custom user attributes that display on front-end profile pages, including a text-type attribute whose display format can be configured to insert the attribute's value inside an HTML tag — for example, a documented "custom link" pattern such as a link element wrapped around a %value% placeholder.
When that display format places the raw value inside an HTML attribute (rather than as plain text), HivePress does not sufficiently sanitize the input on save or escape the output on render. An unauthenticated attacker who can set a value for that attribute — for instance, via a public-facing registration or profile-edit form — can break out of the attribute context and inject a script payload. Because the value is stored in the database, the payload persists and fires for every subsequent visitor who loads the profile page, not just the attacker.
Exploitation requires two preconditions that reflect the plugin's standard, documented configuration rather than a misconfiguration:
- An administrator has configured a text-type custom attribute whose display format places
%value%inside an HTML attribute (e.g.<a href="%value%">Custom link</a>— written here with the placeholder in backticks, not live markup). - Front-end user profiles are enabled, which is the plugin's normal operating mode for directory and listing sites.
Impact Assessment
Who Is At Risk
Any WordPress site running HivePress ≤ 1.7.31 with:
- Front-end user profiles enabled (the plugin's core use case)
- At least one custom text attribute configured to render its value inside an HTML attribute
Potential Attack Chains
- Attribute Injection — An unauthenticated or low-privileged attacker submits a crafted value into the vulnerable custom attribute field through a public profile form
- Persistence — HivePress stores the value without adequate sanitization
- Execution on View — The stored script executes in the browser of any user — including site administrators — who views the affected profile page
- Downstream Compromise — Depending on the payload, this can lead to session/cookie theft, admin account takeover via a logged-in admin viewing the page, or redirection to malicious sites
Because the trigger is simply viewing a page rather than any special privilege, this is a classic stored XSS escalation path from unauthenticated input to administrator-session compromise.
Mitigation
Immediate Actions
- Update to HivePress 1.7.32 or later, which patches the input sanitization and output escaping for custom attribute fields
- Audit existing custom attributes for any text-type field whose display format embeds
%value%inside an HTML attribute, and review stored values for suspicious content (script tags,javascript:URIs, event handler attributes such asonerrororonload) - Review recent profile edits for unexpected or malformed attribute values submitted around the disclosure window
Detection Opportunities
- Search the WordPress database for HivePress attribute values containing angle brackets,
javascript:, or inline event-handler strings - Monitor web server logs for unusual POST requests to profile-edit or registration endpoints immediately preceding the patch release
Defence-in-Depth
- Avoid configuring custom attribute display formats that place user-controlled values inside HTML attributes; prefer plain-text display where possible
- Run a web application firewall rule set that covers stored XSS patterns for WordPress plugins (e.g. Wordfence's firewall rules, which typically ship ahead of public advisories for vulnerabilities its team discovers)
- Keep WordPress core, themes, and all plugins on a regular patch cadence — stored XSS in a directory/listing plugin is a common entry point for broader site compromise
Discovery & Disclosure
The vulnerability was identified by Wordfence's threat intelligence team and disclosed via Patchstack and Wordfence advisories on 2026-10-09 and 2026-10-10 respectively. As of publication, CVE-2026-107657 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit has been observed. Site operators should still prioritize patching given how low the bar is for exploitation — no authentication is required to submit the malicious value.