What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plugin plugin <= 2.5.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plugin plugin <= 2.5.3 versions.
Explanation of Vulnerability in Simple Terms
The Inline Tweet Sharer plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.5.3. An authenticated attacker with high privileges can inject malicious scripts that execute in the browsers of site visitors. The vulnerability requires user interaction to trigger and affects the plugin's tweet-sharing functionality.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view affected pages.
Potential impact on your site
Attackers with admin access can deface content, steal visitor data, or redirect users to malicious sites.
Conditions required to exploit
Administrator or high-privilege account access; victim must view a page containing the injected content.
Key dates
External resources
Related vulnerabilities