What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.
Explanation of Vulnerability in Simple Terms
The Button Generator plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.3.3. An authenticated user with high privileges can inject malicious scripts into button configurations. When other users view pages containing the affected buttons, the scripts execute in their browsers, potentially compromising their sessions or stealing data. The vulnerability requires user interaction to trigger.
What an attacker can do
Inject malicious scripts that execute when other users view pages with the affected buttons.
Potential impact on your site
Compromised user sessions, stolen credentials, or malware distribution to site visitors via trusted admin-created content.
Conditions required to exploit
Attacker must have high-level admin or editor privileges and a victim must view a page containing the malicious button.
Key dates
External resources
Related vulnerabilities