What the vulnerability does
01Description
Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
Explanation of Vulnerability in Simple Terms
The Ezoic WordPress plugin version 2.8.8 and earlier contains a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious scripts into the site. The vulnerability requires user interaction—typically a victim clicking a malicious link—and can affect both the plugin and other parts of the site due to scope change. This could lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers and steals data or performs actions on their behalf.
Potential impact on your site
Visitors' sessions and credentials can be compromised; site reputation and SEO may suffer if malware is distributed.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page; no authentication required.
Key dates
External resources
Related vulnerabilities