What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 versions.
Explanation of Vulnerability in Simple Terms
Visual CSS Style Editor versions up to 7.5.8 contain a cross-site scripting (XSS) vulnerability in the editor interface. An authenticated administrator with high privileges can inject malicious scripts that execute in the browser of another user who views the affected page, potentially compromising their session or stealing sensitive data. The vulnerability requires user interaction and affects the scope beyond the component itself.
What an attacker can do
Inject malicious scripts that execute in another user's browser when they view the editor.
Potential impact on your site
An admin with high privileges could compromise other users' sessions or steal data via script injection in the editor.
Conditions required to exploit
Attacker must have high-level admin privileges and the victim must visit the affected editor page.
Key dates
External resources
Related vulnerabilities