Cross-Site Scripting in UpdraftPlus Plugin Affects WordPress
CVE-2017-18593
6.1MEDIUM
Summary
The UpdraftPlus plugin for WordPress, specifically versions prior to 1.13.5, is susceptible to a Cross-Site Scripting (XSS) vulnerability. In certain scenarios, an attacker can manipulate a string that is logged to the log file, allowing for the injection of malicious scripts. If exploited, this vulnerability could enable an attacker to execute arbitrary scripts in the context of the user's browser, potentially leading to session hijacking or other attacks against users accessing the affected site.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved