What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Noël Jackson Art Direction plugin <= 0.2.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Noël Jackson Art Direction plugin <= 0.2.4 versions.
Explanation of Vulnerability in Simple Terms
Art Direction versions up to 0.2.4 contain a cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject malicious scripts. The vulnerability requires user interaction—typically a victim clicking a malicious link—and can affect other users or the site itself. Low-privileged users can exploit this to steal session data or perform actions on behalf of other users.
What an attacker can do
Inject malicious scripts that execute in other users' browsers or the site admin's browser.
Potential impact on your site
Authenticated users can be tricked into executing attacker-controlled JavaScript, risking session hijacking or unauthorized actions.
Conditions required to exploit
Attacker must have a low-privilege account and trick a user into clicking a malicious link.
Key dates
External resources
Related vulnerabilities