What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <= 3.0.4 versions.
Explanation of Vulnerability in Simple Terms
WordPress Social Login versions up to 3.0.4 contain a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts through the plugin's input fields. When a site visitor or administrator views the affected page, the script executes in their browser, potentially stealing session tokens or performing actions on their behalf. The vulnerability requires user interaction to trigger.
What an attacker can do
Inject malicious scripts that execute when other users view the affected page, stealing credentials or performing unauthorized actions.
Potential impact on your site
Visitors and admins could have their sessions hijacked or be tricked into performing unwanted actions on your site.
Conditions required to exploit
Attacker needs network access and a victim must visit a page containing the injected payload.
Key dates
External resources
Related vulnerabilities