What the vulnerability does
01Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.
Explanation of Vulnerability in Simple Terms
Responsive Tabs for WordPress contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level site access can modify tab content to execute JavaScript in other users' browsers, potentially compromising site functionality or stealing session data. Update to version 4.0.6 or later to fix this issue.
What an attacker can do
Inject JavaScript code that runs in other users' browsers when they view affected tabs.
Potential impact on your site
Malicious users with basic site access can deface content or steal admin session tokens.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., contributor or editor role).
Key dates
External resources
Related vulnerabilities