What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin <= 1.0 version.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin <= 1.0 version.
Explanation of Vulnerability in Simple Terms
Advanced Youtube Channel Pagination versions up to 1.0 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a visitor's browser when they view a page containing the vulnerable component. The attack requires user interaction—the victim must visit a crafted link or page. The vulnerability can affect confidentiality, integrity, and availability of the site.
What an attacker can do
Inject and execute malicious JavaScript in visitors' browsers to steal data, deface content, or redirect users.
Potential impact on your site
Visitors' sessions, credentials, or personal data could be compromised; site content could be altered or defaced.
Conditions required to exploit
No authentication required. Victim must visit a page or click a link containing the malicious payload.
Key dates
External resources
Related vulnerabilities