What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jaytesh Barange Posts Date Ranges posts-date-ranges allows Reflected XSS.This issue affects Posts Date Ranges: from n/a through <= 2.2.
Explanation of Vulnerability in Simple Terms
02Summary
Posts Date Ranges versions 2.2 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in the browsers of site visitors who view affected pages. The vulnerability requires user interaction—a victim must visit a crafted link or page. The impact is limited to the affected component and does not extend to other parts of the site.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in visitors' browsers to steal session tokens, redirect users, or deface content.
Potential impact on your site
04Site Impact
Visitors to your site may have their sessions hijacked, be redirected to malicious sites, or see altered page content.
Conditions required to exploit
05Prerequisites
No authentication required. Victim must visit a page containing the malicious payload (user interaction required).
Key dates
06Disclosure timeline
December 16, 2024
CVE published
May 11, 2026
Record updated