What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy wp tell a friend popup form plugin <= 7.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy wp tell a friend popup form plugin <= 7.1 versions.
Explanation of Vulnerability in Simple Terms
The wp tell a friend popup form plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 7.1. An authenticated administrator can inject malicious JavaScript that executes in the browsers of site visitors. The vulnerability requires an admin to craft a malicious form, and the injected code runs with the privileges of the user viewing the form.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view the affected form.
Potential impact on your site
A compromised admin account can inject code that steals visitor data, redirects users, or performs actions on their behalf.
Conditions required to exploit
Attacker must have WordPress administrator access and the victim must visit a page containing the malicious form.
Key dates
External resources
Related vulnerabilities