What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6.
Explanation of Vulnerability in Simple Terms
WPFunnels versions up to 3.0.6 contain a stored cross-site scripting (XSS) vulnerability that allows high-privilege users to inject malicious scripts. When a victim with sufficient permissions views the affected page, the injected code executes in their browser. The vulnerability requires user interaction and affects the integrity and confidentiality of site data.
What an attacker can do
Inject malicious scripts that execute when high-privilege users view affected pages.
Potential impact on your site
High-privilege user accounts could be compromised or manipulated through script injection on your site.
Conditions required to exploit
Attacker must have high-level privileges in WPFunnels; victim must view the compromised page.
Key dates
External resources
Related vulnerabilities