What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Darko Top Bar allows Stored XSS.This issue affects Top Bar: from n/a through 3.0.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Darko Top Bar allows Stored XSS.This issue affects Top Bar: from n/a through 3.0.5.
Explanation of Vulnerability in Simple Terms
Top Bar versions up to 3.0.5 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts into the top bar configuration. When other users or administrators view pages with the affected top bar, the injected script executes in their browser, potentially compromising their session or stealing sensitive data.
What an attacker can do
Run malicious JavaScript in the browsers of site visitors and administrators.
Potential impact on your site
Administrators with malicious intent can inject scripts that steal session tokens, deface content, or compromise other admin accounts.
Conditions required to exploit
Attacker must have administrator privileges and a victim must view a page containing the affected top bar.
Key dates
External resources
Related vulnerabilities