What the vulnerability does
01Description
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
Explanation of Vulnerability in Simple Terms
The Tabs plugin for wpshopmart contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.5. An authenticated administrator can inject malicious scripts that execute in the browsers of other users viewing the affected content. The vulnerability requires user interaction and affects the integrity and confidentiality of site data.
What an attacker can do
Inject malicious scripts that run in other users' browsers when they view affected content.
Potential impact on your site
Site admins with high privileges can inject scripts affecting other users' sessions and data.
Conditions required to exploit
Administrator account access and victim must view the attacker's crafted content.
Key dates
External resources
Related vulnerabilities