What the vulnerability does
01Description
Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.
Explanation of Vulnerability in Simple Terms
Pop-Up Chop Chop versions 2.1.7 and earlier contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious JavaScript into the plugin's settings. When other users, including administrators, view the affected page, the injected code runs in their browser. This can lead to unauthorized actions or data theft.
What an attacker can do
Inject malicious JavaScript that runs when other users view the plugin's settings page.
Potential impact on your site
Attackers with low-privilege accounts can compromise admin sessions or steal sensitive data from site administrators.
Conditions required to exploit
Attacker must be logged in as a low-privilege user (e.g., contributor or subscriber) and the victim must visit the affected page.
Key dates
External resources
Related vulnerabilities