Executive brief
Dashboard Beacon is a WordPress plugin that provides dashboard enhancements. The plugin contains a stored cross-site scripting (XSS) vulnerability that allows an authenticated administrator to inject malicious JavaScript code into pages served to all site visitors, potentially compromising visitor accounts or stealing sensitive data.
Technical details
The vulnerability is a stored XSS flaw in the janhenckels Dashboard Beacon WordPress plugin (versions up to 1.2.0) caused by improper neutralization of user input during web page generation. An authenticated administrator with sufficient privileges can inject malicious scripts that are stored in the database and executed in the browsers of all users visiting the affected pages. The attack requires administrator-level access or social engineering of a privileged user to perform the injection. No official patch is currently available; mitigation requires plugin update or removal.
Affected products
- janhenckels Dashboard Beacon up to 1.2.0
Timeline
- 2025-10-01: disclosed: Reported by HunSec
- 2025-12-31: advisory: Published by Patchstack