What the vulnerability does
01Description
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions.
Explanation of Vulnerability in Simple Terms
A stored cross-site scripting (XSS) vulnerability exists in Direct Checkout – Quick View – Buy Now For WooCommerce versions up to 1.5.8. An authenticated admin user with high privileges can inject malicious scripts through the plugin's interface. When other users visit affected pages, the injected code executes in their browsers, potentially stealing session data or performing unauthorized actions.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they visit the site.
Potential impact on your site
An admin account compromise could inject malicious code affecting all site visitors, leading to credential theft or malware distribution.
Conditions required to exploit
Attacker must have admin-level access to WordPress and a user must visit a page containing the injected payload.
Key dates
External resources
Related vulnerabilities