What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions.
Explanation of Vulnerability in Simple Terms
The Kanban Boards for WordPress plugin through version 2.5.20 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts into kanban board content. When other users view the affected board, the script executes in their browser, potentially allowing the attacker to steal session tokens or perform actions on their behalf.
What an attacker can do
Inject and execute malicious JavaScript in the browsers of users viewing kanban boards.
Potential impact on your site
A compromised admin account can inject scripts that steal other users' session cookies or perform unauthorized actions.
Conditions required to exploit
Attacker must have administrator privileges and the victim must view the affected kanban board.
Key dates
External resources
Related vulnerabilities