What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in syedamirhussain91 Custom Post custom-post-type-gui allows Stored XSS.This issue affects Custom Post: from n/a through <= 1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in syedamirhussain91 Custom Post custom-post-type-gui allows Stored XSS.This issue affects Custom Post: from n/a through <= 1.0.
Explanation of Vulnerability in Simple Terms
Custom Post versions 1.0 and earlier contain a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without the admin's knowledge. The vulnerability affects the site's integrity and confidentiality due to its changed scope.
What an attacker can do
Trick a logged-in admin into visiting a malicious page that performs unwanted actions on the site.
Potential impact on your site
An attacker can modify site content, settings, or user data by exploiting an admin's active session.
Conditions required to exploit
The victim must be logged in and visit an attacker-controlled webpage or link.
Key dates
External resources
Related vulnerabilities