What the vulnerability does
01Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
Explanation of Vulnerability in Simple Terms
A vulnerability in an unspecified product allows a high-privilege user to modify limited data on the site when they visit a malicious page. The attacker cannot read sensitive information or disrupt service, but can alter content if a site administrator is tricked into clicking a link. The scope extends beyond the vulnerable component itself.
What an attacker can do
Modify limited data on the site if a high-privilege user visits a malicious page.
Potential impact on your site
A compromised admin account or social engineering could allow unauthorized changes to site content or settings.
Conditions required to exploit
High-privilege account (e.g., administrator) and user interaction (victim must visit attacker's page).
Key dates
External resources