What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions.
Explanation of Vulnerability in Simple Terms
CartFlows Pro versions up to 1.11.11 contain a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the site. An attacker can craft a malicious input that, when viewed by site administrators or other users, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.
What an attacker can do
Inject malicious JavaScript that executes in the browsers of site administrators and other users.
Potential impact on your site
Attackers can steal admin session cookies, modify site content, or perform actions as logged-in users without their knowledge.
Conditions required to exploit
User interaction required; victim must view a page containing the attacker's injected payload. No authentication required to inject the payload.
Key dates
External resources
Related vulnerabilities