What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions.
Explanation of Vulnerability in Simple Terms
Easy Hide Login versions up to 1.0.7 contain a cross-site scripting (XSS) vulnerability that allows high-privilege users to inject malicious scripts. An attacker with admin or editor access can craft a request that executes JavaScript in other users' browsers when they interact with the affected page. The vulnerability requires user interaction and affects the integrity and confidentiality of the site.
What an attacker can do
Inject JavaScript that runs in other users' browsers to steal data or perform actions on their behalf.
Potential impact on your site
Admins or editors with malicious intent can compromise other users' sessions and steal sensitive information.
Conditions required to exploit
Attacker must have high-level site access (admin/editor role) and the victim must visit a page containing the malicious payload.
Key dates
External resources
Related vulnerabilities