What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra plugin <= 2.5.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra plugin <= 2.5.2 versions.
Explanation of Vulnerability in Simple Terms
BP Profile Shortcodes Extra versions up to 2.5.2 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts into shortcode parameters. When other users view pages containing the affected shortcodes, the injected code executes in their browsers, potentially allowing session hijacking or credential theft.
What an attacker can do
Inject malicious scripts that execute when other users view affected pages.
Potential impact on your site
Authenticated users can inject persistent XSS payloads affecting all site visitors, risking account compromise and data theft.
Conditions required to exploit
Attacker needs a low-privilege user account and must trick or socially engineer a site admin to view a page with the malicious shortcode.
Key dates
External resources
Related vulnerabilities