XML External Entity Vulnerability in TablePress Plugin by WordPress
CVE-2017-10889

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 November 2017

What is CVE-2017-10889?

A vulnerability in the TablePress plugin, specifically in versions before 1.8.1, allows attackers to conduct XML External Entity (XXE) attacks. This type of attack can enable unauthorized access to sensitive data and facilitate further exploitation through unspecified vectors, posing a significant risk to affected systems.

Affected Version(s)

TablePress prior to version 1.8.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.