What the vulnerability does
01Description
Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
Explanation of Vulnerability in Simple Terms
The Image Slider by NextCode plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 1.1.2. An authenticated administrator with high privileges can inject malicious JavaScript that executes in the browsers of other users viewing the site. The vulnerability requires user interaction and affects the site's integrity and confidentiality.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view the site.
Potential impact on your site
An admin account holder can inject code affecting other users' sessions and data visibility.
Conditions required to exploit
Administrator account required; victim must view a page containing the injected content.
Key dates
External resources
Related vulnerabilities