What the vulnerability does
01Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
Explanation of Vulnerability in Simple Terms
WP Subscribe versions up to 1.2.12 contain a stored cross-site scripting (XSS) vulnerability in the plugin settings. An authenticated administrator with high privileges can inject malicious JavaScript that executes when other users view the affected page. The vulnerability requires user interaction and affects the integrity of the site's content.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view the plugin settings page.
Potential impact on your site
An admin account compromise could allow injection of malicious scripts affecting other administrators or site functionality.
Conditions required to exploit
Attacker must be logged in as an administrator. The victim must visit the affected settings page.
Key dates
External resources
Related vulnerabilities