What the vulnerability does
01Description
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Explanation of Vulnerability in Simple Terms
WPIDE – File Manager & Code Editor versions 3.5.7 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted link or page. The vulnerability affects the scope beyond the plugin itself, potentially compromising user sessions and site data. Update to a version newer than 3.5.7 to remediate.
What an attacker can do
Inject malicious scripts that run in a victim's browser, stealing session tokens or modifying site content.
Potential impact on your site
Users visiting crafted links could have their sessions hijacked or see malicious content injected into the site.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page; no authentication required.
Key dates
External resources
Related vulnerabilities