Multiple XSS Vulnerabilities in Updater Plugin for WordPress
CVE-2017-18565
6.1MEDIUM
What is CVE-2017-18565?
The Updater Plugin for WordPress, prior to version 1.35, contains multiple Cross-Site Scripting (XSS) vulnerabilities. These weaknesses can allow an attacker to execute arbitrary JavaScript in the context of a user’s session, potentially compromising sensitive data or altering the content displayed to users. Website administrators are advised to update to the latest version to mitigate these risks.