What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.
Explanation of Vulnerability in Simple Terms
WP SMS versions up to 6.5.1 contain a stored cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious scripts. When another user views an affected page, the injected code executes in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.
What an attacker can do
Inject malicious JavaScript that executes when other users view the page, potentially stealing credentials or performing unauthorized actions.
Potential impact on your site
An admin account compromise could allow an attacker to inject persistent malicious code affecting all site visitors.
Conditions required to exploit
Attacker must have administrator privileges and the victim must visit a page containing the injected payload.
Key dates
External resources
Related vulnerabilities