Junglewise Threat Intelligence

CVE-2026-57691: Eli Anti-Malware Security and Brute-Force Firewall Reflected XSS

CVE-2026-57691 · Severity: medium · CVSS 5.8 · Published 2026-07-13

Executive brief

A security plugin for WordPress, designed to protect websites from malware and brute-force attacks, is vulnerable to a flaw that could allow attackers to run malicious scripts. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could redirect users to malicious websites, steal session information, or display fraudulent content. This could compromise the integrity of the website and the security of its users.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Eli Anti-Malware Security and Brute-Force Firewall (gotmls) plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows unauthenticated attackers to inject arbitrary web scripts via a crafted URL. Successful exploitation requires a victim (typically a site administrator) to interact with a malicious link or visit a specific page. This can lead to the execution of scripts in the context of the victim's browser, potentially allowing for session hijacking or unauthorized actions. The issue is resolved in version 4.23.90.

Affected products

  • Eli Scheetz Anti-Malware Security and Brute-Force Firewall (gotmls) <= 4.23.89

Timeline

  • 2026-06-23: disclosed: Reported by dutafi to Patchstack
  • 2026-07-09: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-09: patched: Version 4.23.90 released to address the issue

References

Related threats