What the vulnerability does
01Description
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
Explanation of Vulnerability in Simple Terms
The Traffic Manager WordPress plugin version 1.4.5 and earlier contains a vulnerability that allows authenticated users with low privileges to perform actions across the site when a victim visits a malicious page. The vulnerability affects data confidentiality, integrity, and availability. Site administrators should update to a version newer than 1.4.5.
What an attacker can do
Read, modify, or disrupt site data if a logged-in user visits an attacker's page.
Potential impact on your site
Authenticated users' accounts can be abused to alter site content, access sensitive data, or cause service disruption.
Conditions required to exploit
Attacker needs a low-privilege WordPress account; victim must click a malicious link or visit attacker-controlled page.
Key dates
External resources
Related vulnerabilities