What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.
Explanation of Vulnerability in Simple Terms
ShortCodes UI versions up to 1.9.8 contain a stored cross-site scripting vulnerability. An authenticated user with low privileges can inject malicious scripts into shortcode content. When other users view pages containing the affected shortcodes, the injected scripts execute in their browsers. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of victims.
What an attacker can do
Inject malicious scripts that execute when other users view pages with the affected shortcodes.
Potential impact on your site
Authenticated users can inject persistent scripts affecting all site visitors, risking account compromise and data theft.
Conditions required to exploit
Attacker needs a low-privilege user account and must convince or trick a user to view a page with the malicious shortcode.
Key dates
External resources
Related vulnerabilities