What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johannes van Poelgeest Admin Options Pages admin-options-pages allows Reflected XSS.This issue affects Admin Options Pages: from n/a through <= 0.9.7.
Explanation of Vulnerability in Simple Terms
02Summary
Admin Options Pages versions 0.9.7 and earlier contain a cross-site scripting (XSS) vulnerability in how they handle user input on admin pages. An attacker can inject malicious scripts that execute in the browsers of site administrators who visit a crafted link. The vulnerability requires user interaction and can affect multiple users across the site.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in admin browsers, potentially stealing credentials or performing unauthorized actions.
Potential impact on your site
04Site Impact
Admins visiting malicious links could have their sessions compromised or be tricked into performing unintended actions.
Conditions required to exploit
05Prerequisites
An admin must click a malicious link or visit a crafted page; no authentication required from the attacker.
Key dates
06Disclosure timeline
February 14, 2025
CVE published
May 11, 2026
Record updated