Cross-Site Scripting Vulnerability in WP All Import Plugin for WordPress
CVE-2017-18567

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 August 2019

Summary

The WP All Import plugin for WordPress versions prior to 3.4.6 is susceptible to a cross-site scripting vulnerability, which allows attackers to inject malicious scripts. This can compromise the integrity of the application, leading to potential unauthorized access and manipulation of user data. Users are advised to update to the latest version to mitigate these risks. For more information, visit the developer's page.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.