CVE-2026-57384
Received Received - Intake

Subscriber XSS in WishList Member X <= 3.32.0

Vulnerability report for CVE-2026-57384, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Patchstack

Description

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wishlist_member wishlist_member_x to 3.32.0 (inc)
wishlist_member wishlist_member 3.32.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-57384 is a Subscriber Cross Site Scripting (XSS) vulnerability affecting WishList Member X plugin versions 3.32.0 and below. It allows attackers to inject malicious scripts into a website by tricking a privileged user into interacting with a crafted link, page, or form. The vulnerability has a CVSS score of 6.5, indicating moderate severity.

Detection Guidance

Detecting this XSS vulnerability requires monitoring for suspicious activity or reviewing access logs for interactions with the WishList Member X plugin. Check for unusual script injections in user input fields or redirects. No specific commands are provided in the context, but inspecting web server logs for POST/GET requests targeting the plugin and analyzing user-generated content for malicious scripts may help.

Impact Analysis

This vulnerability can allow attackers to inject malicious scripts such as redirects or advertisements into your website. Successful exploitation requires a user with Subscriber or Developer privileges to interact with a malicious link or form. The impact includes potential defacement, data theft, or unauthorized actions on your site.

Mitigation Strategies

Immediately update the WishList Member X plugin to version 3.33.0 or later to patch the vulnerability. Apply Patchstack's mitigation rule to block attacks until the update is completed. Restrict user privileges to the minimum required, especially for Subscriber or Developer roles, to reduce exploitation risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57384. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart