What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
Explanation of Vulnerability in Simple Terms
WP Clictracker versions up to 1.0.5 contain a cross-site scripting (XSS) vulnerability that allows authenticated users with high privileges to inject malicious scripts. The vulnerability requires user interaction to trigger. An attacker with admin or editor access can craft a malicious link that, when clicked by another user, executes JavaScript in their browser session, potentially compromising their account or stealing sensitive data.
What an attacker can do
Inject JavaScript code that runs in other users' browsers when they click a malicious link.
Potential impact on your site
A malicious admin or editor can steal session tokens or credentials from other users, or deface site content.
Conditions required to exploit
Attacker must have high-level site privileges (admin/editor). Victim must click the attacker's crafted link.
Key dates
External resources
Related vulnerabilities