What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MailOptin Popup Builder Team MailOptin plugin <= 1.2.54.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MailOptin Popup Builder Team MailOptin plugin <= 1.2.54.0 versions.
Explanation of Vulnerability in Simple Terms
MailOptin versions up to 1.2.54.0 contain a cross-site scripting vulnerability in the popup builder. An authenticated user with high privileges can inject malicious scripts that execute in other users' browsers when they interact with the affected component. The vulnerability requires user interaction to trigger. Update to version 1.2.77.3 or later.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view or interact with popups.
Potential impact on your site
An admin could inject scripts affecting other users' sessions, potentially stealing credentials or modifying site content they see.
Conditions required to exploit
Attacker must have high-level admin privileges and the victim must click a link or visit a page containing the malicious popup.
Key dates
External resources
Related vulnerabilities