What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
Explanation of Vulnerability in Simple Terms
Dynamically Register Sidebars versions up to 1.0.1 contain a cross-site scripting (XSS) vulnerability in sidebar configuration handling. An authenticated administrator with high privileges can inject malicious scripts that execute in other users' browsers when they interact with affected pages. The vulnerability requires user interaction and can affect the integrity and confidentiality of site data.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view or interact with sidebar settings.
Potential impact on your site
Administrators with high privileges could inject scripts affecting other users' sessions and data on your site.
Conditions required to exploit
Attacker must have administrator-level access and the victim must visit an affected page or interact with a sidebar.
Key dates
External resources
Related vulnerabilities