What the vulnerability does
01Description
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.
Explanation of Vulnerability in Simple Terms
The History Timeline WordPress plugin version 1.0.5 and earlier contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious JavaScript that executes in the browsers of other site users. The vulnerability requires an admin to intentionally craft malicious input, and the injected code runs with the privileges of the user viewing the affected page.
What an attacker can do
Inject JavaScript that runs in other users' browsers when they view the plugin's content.
Potential impact on your site
A compromised admin account can inject malicious scripts affecting other users' sessions and data.
Conditions required to exploit
Administrator account access and user interaction (victim must view the affected page).
Key dates
External resources
Related vulnerabilities