What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.
Explanation of Vulnerability in Simple Terms
Hero Banner Ultimate through version 1.3.4 contains a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts into banner content. When other users view the affected banner, the script executes in their browser, potentially allowing the attacker to steal session tokens, redirect users, or perform actions on their behalf.
What an attacker can do
Inject malicious scripts that execute when other users view the banner, stealing sessions or performing unauthorized actions.
Potential impact on your site
Authenticated users can inject persistent malicious code affecting all site visitors who view banners, compromising user accounts and site integrity.
Conditions required to exploit
Attacker must have a low-privilege user account and the victim must view the compromised banner.
Key dates
External resources
Related vulnerabilities