Junglewise Threat Intelligence

CVE-2026-57351: Haktan Suren HandL UTM Grabber unauthenticated XSS

CVE-2026-57351 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

HandL UTM Grabber, a WordPress plugin used to track marketing campaign data, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site visitor or administrator clicks a specially crafted link, the attacker can execute code in their browser, potentially leading to unauthorized redirects, theft of session information, or website defacement. This vulnerability can be exploited by remote attackers without needing a password.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the HandL UTM Grabber plugin for WordPress (versions <= 2.9.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a victim to interact with a malicious link or crafted page (User Interaction: Required). The vulnerability was addressed in version 2.9.3.

Affected products

  • Haktan Suren HandL UTM Grabber <= 2.9.2

Timeline

  • 2026-06-09: other: Reported by researcher Ananda Dhakal
  • 2026-07-01: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: NVD publication date
  • 2026-07-01: patched: Version 2.9.3 released to address the issue

References