CVE-2026-53737: Juicer XSS Vulnerability in Admin Settings – CVSS 6.1 Analysis
Juicer, a plugin or tool for managing remote feeds, contains a stored cross-site scripting (XSS) vulnerability in versions through 1.12.18. When an administrator visits the plugin's settings page, the plugin fails to properly sanitize data pulled from a connected remote feed before displaying it. An attacker who controls or can manipulate that feed source can inject malicious JavaScript code that will execute in the administrator's browser session. This runs with the privileges of the logged-in admin, potentially allowing the attacker to perform unauthorized actions or steal sensitive information.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.1 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-10 / 2026-06-17
NVD description (verbatim)
Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability is a reflected/stored XSS flaw (CWE-79) in Juicer's admin settings interface. The plugin retrieves data from remote feed APIs and renders response fields directly into the admin settings page without proper HTML encoding or escaping. An attacker who can control the feed source (or perform a man-in-the-middle attack on the API communication) can inject arbitrary HTML and JavaScript payloads. When an administrator loads the settings page, the injected script executes in their browser context, including within the same-origin policy scope. The CVSS 3.1 score of 6.1 (MEDIUM, vector CVSS:3.1/AV:N/AC:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) reflects network accessibility, low attack complexity, no authentication requirement, required user interaction (admin clicking the settings page), changed scope, and limited confidentiality and integrity impact.
Business impact
Compromised administrator accounts can lead to unauthorized changes to site configuration, content injection, malware distribution, or theft of sensitive data. The attack requires an attacker to control a feed source and an administrator to visit settings, making it well-suited to supply-chain scenarios or compromised feed endpoints. Depending on what the compromised admin account can do, impacts could extend to the entire site or platform.
Affected systems
Juicer versions 1.12.18 and earlier are affected. The attack surface is limited to administrators or users with permissions to access the plugin's settings page, but any attacker controlling a connected feed can exploit it.
Exploitability
The vulnerability requires no authentication from the attacker's perspective but does require user interaction: an administrator must visit the settings page after the attacker has injected a payload into a connected feed. Exploitability is moderate; while the initial injection may require feed compromise or interception, execution is guaranteed once the admin loads settings. There is no known public exploit code, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
Remediation
Upgrade Juicer to a version that properly escapes feed API response fields before rendering them in the admin interface. Check with the vendor or project maintainers for an available patch above version 1.12.18. As a temporary mitigation, restrict admin access to trusted networks or monitor feed sources for suspicious modifications.
Patch guidance
Verify the latest version of Juicer available from the official vendor or repository. Apply the patch as soon as a version addressing this XSS vulnerability is released. Test the update in a staging environment to ensure compatibility with your configuration and other plugins. Confirm that feed data is now properly sanitized by reviewing admin settings after patching.
Detection guidance
Monitor for unexpected changes to feed configuration or unusual JavaScript appearing in feed API responses. Review admin access logs for settings page visits, especially after feed data changes. Use a Web Application Firewall (WAF) or browser security extension to detect and block inline script execution in the admin interface. Implement Content Security Policy (CSP) headers if not already in place to limit the blast radius of injected scripts.
Why prioritize this
Although the CVSS score is MEDIUM, this vulnerability should be prioritized because it directly affects administrator accounts, which are high-value targets. Exploitation requires only feed compromise and admin site access, not sophisticated attack chains. Organizations running Juicer in production and connecting it to external feeds should patch immediately.
Risk score, explained
The CVSS 3.1 score of 6.1 (MEDIUM) reflects that exploitation requires both attacker capability to control a feed and user interaction (admin visiting settings). The changed scope (S:C) indicates the impact can affect resources beyond the vulnerable component. Limited confidentiality and integrity impact (C:L/I:L) acknowledges that the attack runs in the admin's browser but does not directly compromise the server or application data storage. However, the admin context means an attacker can still perform many harmful actions.
Frequently asked questions
Does this vulnerability require the attacker to have existing credentials or access to Juicer?
No. The attacker only needs to control or compromise the remote feed source that Juicer connects to. They do not need direct access to the Juicer installation or any administrator credentials. However, they do need an administrator to visit the settings page for the payload to execute.
Can this vulnerability allow an attacker to take over the entire website or server?
Not directly from the browser XSS alone. However, once malicious JavaScript runs in an administrator's browser, the attacker can use the admin's session to perform any action the admin is authorized to do. This could include changing settings, injecting content, creating new admin accounts, or installing backdoors, depending on what the admin account can access.
What should I do if I'm not sure what version of Juicer I'm running?
Check the plugin settings or administration panel for version information. If unavailable, consult the plugin's repository or contact the vendor. Once you know your version, compare it against the affected range (1.12.18 and earlier) and apply a patch if necessary.
Are there any workarounds if I cannot patch immediately?
While a patch is the best solution, you can reduce risk by restricting access to the Juicer settings page to trusted IP addresses, monitoring feed sources for malicious modifications, and implementing a strong Content Security Policy header. However, these are temporary measures and should not replace patching.
This analysis is based on publicly available vulnerability data as of the publication date. Vendor information, patch availability, and KEV status may change; consult official vendor advisories for the most current information. This write-up does not constitute security advice or a recommendation to perform any specific action. Organizations should evaluate their own risk tolerance and operational constraints before applying patches or implementing mitigations. SEC.co assumes no liability for actions taken in response to this intelligence. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide