CVE-2026-34890
Received Received - Intake
DOM-Based XSS in MSTW League Manager Allows Client-Side Attacks

Publication date: 2026-04-02

Last updated on: 2026-04-02

Assigner: Patchstack

Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: from n/a through 2.10.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-02
Last Modified
2026-04-02
Generated
2026-06-16
AI Q&A
2026-04-02
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
mark_o_donnell mstw_league_manager to 2.10 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-34890 is a Cross Site Scripting (XSS) vulnerability affecting the WordPress MSTW League Manager Plugin versions up to and including 2.10.

This vulnerability allows attackers to inject malicious scripts—such as redirects, advertisements, or other HTML payloads—into websites, which execute when visitors access the compromised site.

Exploitation requires a user with at least Contributor-level privileges to perform an action like clicking a malicious link, visiting a crafted page, or submitting a form, meaning user interaction is necessary.

The vulnerability is classified under OWASP Top 10 category A3: Injection and has a CVSS severity score of 6.5, indicating a moderate risk.

Impact Analysis

This vulnerability can impact you by allowing attackers to inject and execute malicious scripts on your website.

These scripts can perform actions such as redirecting visitors to malicious sites, displaying unwanted advertisements, or executing other harmful HTML payloads.

Because exploitation requires user interaction and at least Contributor-level privileges, the risk is somewhat limited but still significant.

The overall impact includes potential compromise of user data, loss of trust, and possible disruption of website functionality.

Detection Guidance

This vulnerability is a DOM-Based Cross-Site Scripting (XSS) issue affecting the MSTW League Manager WordPress plugin up to version 2.10. Detection typically involves identifying attempts to inject malicious scripts via user interactions such as clicking links, visiting crafted pages, or submitting forms.

Since the vulnerability requires user interaction and affects web page generation, detection can be approached by monitoring web server logs for suspicious input patterns or unusual query parameters that might contain script tags or encoded payloads.

Specific commands are not provided in the available resources, but general approaches include using web application scanners that detect XSS vulnerabilities or employing manual testing with payloads designed to trigger DOM-based XSS.

Mitigation Strategies

Currently, there is no official patch available for this vulnerability in the MSTW League Manager plugin.

The recommended immediate mitigation steps are to monitor for updates and apply the plugin update once a patch is released.

In the meantime, it is advised to seek assistance from hosting providers or web developers to implement rapid mitigation services or other protective measures.

Additionally, limiting user privileges to reduce the number of users with Contributor-level access can reduce the risk of exploitation.

Compliance Impact

CVE-2026-34890 is a Cross Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into websites, potentially compromising user data and site integrity.

Such vulnerabilities can impact compliance with standards like GDPR and HIPAA because they may lead to unauthorized access or exposure of personal or sensitive data through malicious script execution.

However, the provided information does not explicitly discuss the direct effects of this vulnerability on compliance with these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34890. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart