What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb ur Rehman Simple PopUp plugin <= 1.8.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb ur Rehman Simple PopUp plugin <= 1.8.6 versions.
Explanation of Vulnerability in Simple Terms
Simple PopUp versions up to 1.8.6 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious JavaScript into popup content that executes in the browsers of site visitors. The vulnerability requires an admin to create or edit a popup and a user to view the affected page. This can lead to session hijacking, credential theft, or malware distribution to site visitors.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view a popup.
Potential impact on your site
A compromised admin account can inject malware or steal visitor data through popups without code access.
Conditions required to exploit
Attacker must have administrator privileges and a visitor must view the page containing the popup.
Key dates
External resources
Related vulnerabilities