What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions.
Explanation of Vulnerability in Simple Terms
The IFrame Shortcode plugin contains a cross-site scripting (XSS) vulnerability in versions up to 1.0.5. An authenticated user with low privileges can inject malicious scripts into iframe shortcodes. When another user views a page containing the affected shortcode, the injected script executes in their browser, potentially allowing the attacker to steal session tokens or perform actions on their behalf.
What an attacker can do
Inject and execute malicious JavaScript in other users' browsers via iframe shortcode content.
Potential impact on your site
Authenticated users can inject scripts that compromise other visitors' sessions and data without admin intervention.
Conditions required to exploit
Attacker must have a low-privilege user account and the victim must view a page with the malicious shortcode.
Key dates
External resources
Related vulnerabilities