What the vulnerability does
01Description
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
Explanation of Vulnerability in Simple Terms
WPMobile.App versions 11.13 and earlier contain a cross-site scripting vulnerability that allows an attacker to inject malicious scripts into the application. An authenticated user must visit a crafted page or link for the attack to succeed. The vulnerability can affect the confidentiality, integrity, and availability of user data within the application's scope.
What an attacker can do
Inject and execute malicious scripts in the app to steal data, modify content, or disrupt functionality.
Potential impact on your site
Users' accounts and data are at risk if they visit attacker-controlled content while logged into the app.
Conditions required to exploit
Attacker needs a valid user account and must trick a user into visiting a malicious link or page.
Key dates
External resources
Related vulnerabilities