What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.
Explanation of Vulnerability in Simple Terms
The Tabs plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability in versions up to 4.0.6. An authenticated administrator can inject malicious JavaScript into tab content that executes in the browsers of other users viewing the affected page. The vulnerability requires user interaction and affects the integrity and confidentiality of site data.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view tabs.
Potential impact on your site
Administrators can be tricked into injecting malicious code affecting all site visitors.
Conditions required to exploit
Administrator account access and victim must view the affected tab content.
Key dates
External resources
Related vulnerabilities