What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 versions.
Explanation of Vulnerability in Simple Terms
WP BrowserUpdate through version 4.5 contains a cross-site scripting (XSS) vulnerability that allows an authenticated administrator to inject malicious scripts. The vulnerability requires user interaction—typically clicking a malicious link—and can affect other users on the site. An attacker with admin privileges can craft a payload that executes in the browsers of site visitors.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they interact with the site.
Potential impact on your site
A compromised admin account can inject scripts affecting all site visitors, potentially stealing data or redirecting users.
Conditions required to exploit
Attacker must have administrator access and the victim must click a link or visit a page containing the payload.
Key dates
External resources
Related vulnerabilities