Cross-site Scripting Vulnerability in Brainstorm Force Starter Templates
CVE-2026-102393

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-102393?

A Cross-site Scripting (XSS) vulnerability was identified in Brainstorm Force's Starter Templates, affecting versions from n/a to 4.7.7. This security flaw arises from improper neutralization of user input during web page generation, potentially allowing attackers to inject malicious scripts that get executed in the context of users accessing the affected pages. As a result, the attack may lead to unauthorized actions being performed on behalf of legitimate users, data theft, or other malicious activities. Users of the affected versions are recommended to apply the necessary updates to mitigate the risk associated with this vulnerability.

Affected Version(s)

Starter Templates 0 <= 4.7.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

fcc | Patchstack Bug Bounty Program
.