Cross-Site Scripting Flaws in Custom Admin Page for WordPress
CVE-2017-18493

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
13 August 2019

What is CVE-2017-18493?

The Custom Admin Page plugin for WordPress, prior to version 0.1.2, is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities. These security flaws may allow attackers to inject malicious scripts, compromising the integrity of the web application and putting user data at risk. Website administrators and users should update to the latest version to mitigate these risks and enhance security measures.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.