Cross-Site Scripting in UpdraftPlus Plugin Affects WordPress
CVE-2017-18593

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
28 August 2019

What is CVE-2017-18593?

The UpdraftPlus plugin for WordPress, specifically versions prior to 1.13.5, is susceptible to a Cross-Site Scripting (XSS) vulnerability. In certain scenarios, an attacker can manipulate a string that is logged to the log file, allowing for the injection of malicious scripts. If exploited, this vulnerability could enable an attacker to execute arbitrary scripts in the context of the user's browser, potentially leading to session hijacking or other attacks against users accessing the affected site.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.