What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions.
Explanation of Vulnerability in Simple Terms
The Newsletter & Bulk Email Sender plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.0.1. An authenticated user with low privileges can inject malicious scripts into newsletter content. When other users view or interact with the affected newsletter, the injected code executes in their browser, potentially allowing the attacker to steal session tokens, modify page content, or perform actions on their behalf.
What an attacker can do
Inject malicious JavaScript that executes when other users view newsletters, stealing their session data or performing actions as them.
Potential impact on your site
Compromised user accounts, defaced newsletters, and potential unauthorized administrative actions if a high-privilege user views the malicious content.
Conditions required to exploit
Attacker needs a low-privilege WordPress account and must trick a user into viewing a newsletter containing the malicious payload.
Key dates
External resources
Related vulnerabilities