Cross-Site Scripting in UpdraftPlus Plugin Affects WordPress
CVE-2017-18593

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 August 2019

Summary

The UpdraftPlus plugin for WordPress, specifically versions prior to 1.13.5, is susceptible to a Cross-Site Scripting (XSS) vulnerability. In certain scenarios, an attacker can manipulate a string that is logged to the log file, allowing for the injection of malicious scripts. If exploited, this vulnerability could enable an attacker to execute arbitrary scripts in the context of the user's browser, potentially leading to session hijacking or other attacks against users accessing the affected site.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.