What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
Explanation of Vulnerability in Simple Terms
CPO Content Types through version 1.1.0 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts into the plugin's content fields. When other users view the affected content, the scripts execute in their browsers, potentially compromising their sessions or stealing sensitive data. The vulnerability requires user interaction—the victim must visit a page containing the injected script.
What an attacker can do
Inject malicious scripts that execute when other site users view the affected content.
Potential impact on your site
Compromised user sessions, credential theft, or malware distribution to site visitors via admin-injected content.
Conditions required to exploit
Attacker must have high-level admin privileges and the victim must visit a page with the injected script.
Key dates
External resources
Related vulnerabilities