What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Everest News theme <= 1.1.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Everest News theme <= 1.1.0 versions.
Explanation of Vulnerability in Simple Terms
Everest News versions up to 1.1.0 contain a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the site. An attacker can craft a malicious link or page that, when visited by a site administrator or user, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.
What an attacker can do
Inject malicious JavaScript that executes in users' browsers when they visit affected pages.
Potential impact on your site
Attackers can steal admin sessions, modify site content, or harvest user credentials through injected scripts.
Conditions required to exploit
Attacker needs a victim to click a malicious link or visit a compromised page (user interaction required).
Key dates
External resources
Related vulnerabilities