What the vulnerability does
01Description
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
Explanation of Vulnerability in Simple Terms
WP Terms Popup versions up to 2.6.0 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious JavaScript into popup content. When other users view the affected popup, the script executes in their browser, potentially compromising their session or stealing data. The vulnerability requires user interaction—victims must visit a page displaying the popup.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view a popup.
Potential impact on your site
Attackers with admin access can compromise visitor sessions or steal data via popup content.
Conditions required to exploit
Administrator account access and victim must view the affected popup.
Key dates
External resources
Related vulnerabilities