What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions.
Explanation of Vulnerability in Simple Terms
WordPress Popular Posts plugin versions up to 6.3.2 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts through plugin settings. When other users, including administrators, view affected pages, the injected code executes in their browsers. This can lead to account compromise or unauthorized actions.
What an attacker can do
Inject malicious scripts that execute when other users view the site, potentially stealing credentials or performing actions as those users.
Potential impact on your site
Attackers with contributor or subscriber access can compromise admin accounts or modify site content through stored XSS attacks.
Conditions required to exploit
Attacker must have a low-privilege WordPress account and the victim must view a page containing the vulnerable plugin output.
Key dates
External resources
Related vulnerabilities