What the vulnerability does
01Description
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 versions.
Explanation of Vulnerability in Simple Terms
Regina Lite contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts into the site. When other users view the affected content, the scripts execute in their browsers, potentially compromising their sessions or stealing data. The vulnerability requires user interaction to trigger and affects the site's scope beyond the vulnerable component.
What an attacker can do
Inject malicious scripts that execute when other users view the affected content.
Potential impact on your site
Authenticated users can inject scripts affecting other visitors; session hijacking or data theft possible.
Conditions required to exploit
Attacker must be authenticated with low-level privileges; victim must view the page containing the injected script.
Key dates
External resources
Related vulnerabilities