What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-Buddy Google Analytics Opt-Out plugin <= 2.3.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-Buddy Google Analytics Opt-Out plugin <= 2.3.4 versions.
Explanation of Vulnerability in Simple Terms
The Google Analytics Opt-Out plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.3.4. An authenticated administrator can inject malicious JavaScript that executes in the browsers of other site users. The vulnerability requires an admin to craft and save a malicious input, and the injected code runs with the privileges of the user viewing the affected page.
What an attacker can do
Inject JavaScript that runs in other users' browsers when they view the site.
Potential impact on your site
A compromised admin account can inject malicious scripts affecting all site visitors, potentially stealing credentials or redirecting users.
Conditions required to exploit
Administrator account access and user interaction (victim must view the page with injected content).
Key dates
External resources
Related vulnerabilities