What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker allows Stored XSS.This issue affects Table Maker: from n/a through 1.9.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker allows Stored XSS.This issue affects Table Maker: from n/a through 1.9.1.
Explanation of Vulnerability in Simple Terms
Table Maker through version 1.9.1 contains a stored cross-site scripting (XSS) vulnerability. An authenticated admin can inject malicious scripts into table data that execute in other users' browsers when they view the table. The vulnerability requires admin privileges and user interaction to exploit, but can affect site visitors across the application.
What an attacker can do
Inject malicious scripts that run in visitors' browsers when they view affected tables.
Potential impact on your site
A compromised admin account can inject scripts affecting all site visitors who view tables, potentially stealing credentials or redirecting users.
Conditions required to exploit
Admin-level access to the plugin and a victim must view the compromised table.
Key dates
External resources
Related vulnerabilities