What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions.
Explanation of Vulnerability in Simple Terms
WP Popups versions up to 2.1.4.8 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts into popup content. When other users view the affected popups, the scripts execute in their browsers, potentially allowing the attacker to steal session tokens, redirect users, or perform actions on their behalf.
What an attacker can do
Inject malicious scripts that execute when other users view popups, stealing sessions or performing unauthorized actions.
Potential impact on your site
Visitors and administrators viewing popups may have their sessions hijacked or be redirected to malicious sites without their knowledge.
Conditions required to exploit
Attacker needs a low-privilege WordPress account and the victim must view a popup containing the injected script.
Key dates
External resources
Related vulnerabilities