What the vulnerability does
01Description
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
Explanation of Vulnerability in Simple Terms
A stored cross-site scripting (XSS) vulnerability exists in the Manual WordPress theme through version 7.5.4. An authenticated user with low privileges can inject malicious scripts that execute in the browsers of other site visitors, potentially compromising their sessions or stealing sensitive data. The vulnerability requires user interaction to trigger and affects the site's integrity and confidentiality.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view affected pages.
Potential impact on your site
Visitor accounts and data can be compromised; site reputation and user trust are at risk.
Conditions required to exploit
Attacker must have a low-privilege WordPress account and trick a site visitor into viewing a page containing the injected payload.
Key dates
External resources
Related vulnerabilities