What the vulnerability does
01Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
Explanation of Vulnerability in Simple Terms
The Launcher: Coming Soon & Maintenance Mode plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 1.0.11. An authenticated administrator with high privileges can inject malicious scripts through plugin settings. When other users view affected pages, the injected code executes in their browsers, potentially compromising their sessions or stealing data.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view the site.
Potential impact on your site
A compromised admin account can inject persistent malware affecting all site visitors without leaving obvious traces.
Conditions required to exploit
Attacker must be logged in as an administrator or high-privilege user and the victim must visit an affected page.
Key dates
External resources
Related vulnerabilities