What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Zia Imtiaz Custom Login Page Styler for WordPress plugin <= 6.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Zia Imtiaz Custom Login Page Styler for WordPress plugin <= 6.2 versions.
Explanation of Vulnerability in Simple Terms
Custom Login Page Styler for WordPress versions up to 6.2 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts through the plugin's settings. When other users view affected pages, the injected code executes in their browsers, potentially compromising their sessions or stealing sensitive data.
What an attacker can do
Inject and store malicious JavaScript that executes when other users view the login page.
Potential impact on your site
Compromised admin accounts can inject persistent malware affecting all site visitors and potentially stealing login credentials.
Conditions required to exploit
Attacker must have administrator-level access to WordPress and a user must visit the affected login page.
Key dates
External resources
Related vulnerabilities