What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aazztech WP Cookie wp-cookie allows Stored XSS.This issue affects WP Cookie: from n/a through <= 1.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aazztech WP Cookie wp-cookie allows Stored XSS.This issue affects WP Cookie: from n/a through <= 1.0.0.
Explanation of Vulnerability in Simple Terms
WP Cookie versions 1.0.0 and earlier contain a cross-site scripting (XSS) vulnerability that allows a high-privilege user to inject malicious scripts. The vulnerability requires user interaction and affects the scope beyond the vulnerable component. An attacker with administrative or editor-level access can craft a malicious request that, when visited by another user, executes arbitrary JavaScript in their browser.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they visit the site.
Potential impact on your site
A compromised admin or editor account can steal session tokens, modify site content, or redirect users to malicious sites.
Conditions required to exploit
Attacker must have high-level site privileges (admin or editor role) and the victim must visit a crafted link or page.
Key dates
External resources
Related vulnerabilities