What the vulnerability does
01Description
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.
Explanation of Vulnerability in Simple Terms
iQ Block Country version 1.2.11 contains a cross-site scripting (XSS) vulnerability that allows administrators to inject malicious scripts. The vulnerability affects the scope beyond the vulnerable component itself. An attacker with high-level privileges can craft input that executes in other users' browsers, potentially compromising site security or user data.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view affected pages.
Potential impact on your site
A compromised admin account could inject scripts affecting all site visitors, potentially stealing credentials or modifying site content.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities