What the vulnerability does
01Description
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin <= 2.5.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin <= 2.5.4 versions.
Explanation of Vulnerability in Simple Terms
Forms for Mailchimp by Optin Cat versions up to 2.5.4 contain a stored cross-site scripting (XSS) vulnerability. An authenticated admin can inject malicious scripts into form fields that execute in other users' browsers when they view the form. The vulnerability requires admin privileges and user interaction to exploit, but can affect site visitors and other administrators.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they interact with the form.
Potential impact on your site
A compromised admin account can inject scripts to steal data from site visitors or other admins.
Conditions required to exploit
Admin-level access to the site and the victim must view the affected form or page.
Key dates
External resources
Related vulnerabilities