🔐 CVE Alert

CVE-2026-107657

HIGH 7.2

HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribute Value via Registration Form

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have configured a text-type custom user attribute whose display format places %value% inside an HTML attribute context (e.g., the documented pattern &lt;a href="%value%"&gt;Custom link&lt;/a&gt;), and for front-end user profiles to be enabled — both of which reflect the plugin's standard, documented configuration.

CWE CWE-79
Vendor hivepress
Product hivepress – business directory, listings & classified ads plugin
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for hivepress hivepress – business directory, listings & classified ads plugin

Be the first to know when new high vulnerabilities affecting hivepress hivepress – business directory, listings & classified ads plugin are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

hivepress / HivePress – Business Directory, Listings & Classified Ads Plugin
0 ≤ 1.7.31

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/d0e73b59-58d7-4f4b-b7f3-568190be9b09?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/hivepress/tags/1.7.31/includes/helpers.php#L382 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/hivepress/tags/1.7.31/includes/fields/class-field.php#L561 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/hivepress/tags/1.7.31/includes/fields/class-text.php#L197 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/hivepress/tags/1.7.31/includes/components/class-attribute.php#L1298 github.com: https://github.com/hivepress/hivepress/releases/tag/1.7.32

Credits

Adrien Brunner