What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions.
Explanation of Vulnerability in Simple Terms
Daily Prayer Time contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. When another user views the affected content, the script executes in their browser, potentially compromising their session or stealing sensitive data. The vulnerability requires user interaction to trigger and affects versions up to 2023.05.04.
What an attacker can do
Inject malicious scripts that execute when other users view the affected content, potentially stealing their session data or credentials.
Potential impact on your site
Authenticated users can inject scripts affecting other users' sessions and data; site reputation and user trust at risk.
Conditions required to exploit
Attacker must have a low-privilege user account and the victim must view the page containing the injected script.
Key dates
External resources
Related vulnerabilities