What the vulnerability does
01Description
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
Explanation of Vulnerability in Simple Terms
The Survey Maker WordPress plugin version 2.0.6 and earlier contains a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious JavaScript into survey content that executes in the browsers of site visitors. The vulnerability requires user interaction—a victim must view a page containing the malicious survey. This can lead to session hijacking, credential theft, or malware distribution to site visitors.
What an attacker can do
Inject JavaScript code that runs in visitors' browsers when they view a survey.
Potential impact on your site
Site visitors could have their sessions hijacked, credentials stolen, or be redirected to malicious sites.
Conditions required to exploit
No authentication required. A victim must view a page containing the malicious survey.
Key dates
External resources
Related vulnerabilities