What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 versions.
Explanation of Vulnerability in Simple Terms
Top 25 Social Icons contains a stored cross-site scripting (XSS) vulnerability in versions up to 3.1. An authenticated user with low privileges can inject malicious scripts that execute in the browsers of other site visitors, including administrators. The vulnerability requires user interaction to trigger and can affect the entire site scope.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view affected pages.
Potential impact on your site
Attackers with low-privilege accounts can deface content, steal admin credentials, or compromise other users visiting your site.
Conditions required to exploit
Attacker must have a low-privilege authenticated account and trick a user into visiting a page with the malicious payload.
Key dates
External resources
Related vulnerabilities