What the vulnerability does
01Description
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
Explanation of Vulnerability in Simple Terms
The Responsive Tabs WordPress plugin through version 4.0.5 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious JavaScript into tab content that executes in the browsers of site visitors. The vulnerability requires an admin to intentionally craft malicious input, and the injected script runs with the privileges of the affected user's session.
What an attacker can do
Inject JavaScript that runs in visitors' browsers when they view pages with the plugin's tabs.
Potential impact on your site
A compromised admin account can inject malicious scripts affecting all site visitors, potentially stealing credentials or redirecting users.
Conditions required to exploit
Attacker must have WordPress administrator privileges and the victim must visit a page containing the malicious tab.
Key dates
External resources
Related vulnerabilities