What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asdqwe Dev Ajax Domain Checker plugin <= 1.3.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asdqwe Dev Ajax Domain Checker plugin <= 1.3.0 versions.
Explanation of Vulnerability in Simple Terms
Ajax Domain Checker versions up to 1.3.0 contain a cross-site scripting (XSS) vulnerability. An attacker with low-level user access can inject malicious scripts that execute in other users' browsers when they interact with the affected component. The vulnerability requires user interaction and can affect confidentiality, integrity, and availability of the site.
What an attacker can do
Inject malicious scripts that run in other users' browsers to steal data, modify content, or perform actions on their behalf.
Potential impact on your site
Users' sessions and data can be compromised; attackers can deface content or redirect users to malicious sites.
Conditions required to exploit
Attacker needs low-level user account access and must trick a victim into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities