What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions.
Explanation of Vulnerability in Simple Terms
Restrict versions up to 2.2.4 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts. The vulnerability requires user interaction—typically clicking a malicious link—and affects the integrity and confidentiality of site data. The impact extends beyond the vulnerable component itself.
What an attacker can do
Inject malicious scripts that execute in users' browsers and steal data or perform actions on their behalf.
Potential impact on your site
Site visitors' sessions and data can be compromised if they interact with attacker-controlled content.
Conditions required to exploit
Attacker must trick a user into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities