What the vulnerability does
01Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The MashShare WordPress plugin through version 3.8.1 contains a stored cross-site scripting (XSS) vulnerability in its social media sharing functionality. An authenticated administrator with high privileges can inject malicious JavaScript that executes in the browsers of site visitors. The vulnerability requires user interaction and affects the integrity of the site's frontend content.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view affected pages.
Potential impact on your site
Visitors' browsers can be compromised to steal data, redirect traffic, or deface content displayed on your site.
Conditions required to exploit
Attacker must be logged in as an administrator and trick a user into visiting a crafted link or page.
Key dates
External resources
Related vulnerabilities