What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timersys WP Popups allows Stored XSS.This issue affects WP Popups: from n/a through 2.1.5.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timersys WP Popups allows Stored XSS.This issue affects WP Popups: from n/a through 2.1.5.5.
Explanation of Vulnerability in Simple Terms
WP Popups versions up to 2.1.5.5 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with high privileges can inject malicious scripts into popup content. When other users view the affected popups, the scripts execute in their browsers, potentially compromising their sessions or stealing data. The vulnerability requires user interaction to trigger the payload.
What an attacker can do
Inject malicious scripts that execute when other users view popups, potentially stealing session data or credentials.
Potential impact on your site
Compromised admin accounts could inject persistent malicious code affecting all site visitors who see popups.
Conditions required to exploit
Attacker must have high-level admin privileges and a victim must view the affected popup.
Key dates
External resources
Related vulnerabilities