What the vulnerability does
01Description
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
Explanation of Vulnerability in Simple Terms
WordPress Popular Posts versions 5.3.3 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious JavaScript that executes in the browsers of other site users. The vulnerability affects the plugin's scope across the site, potentially compromising user sessions and data. Update to a version newer than 5.3.3.
What an attacker can do
Inject JavaScript that runs in other users' browsers when they view affected pages.
Potential impact on your site
A compromised admin account can inject malicious scripts affecting all site visitors and other administrators.
Conditions required to exploit
Attacker must have administrator privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities