Cross-Site Scripting in UpdraftPlus Plugin Affects WordPress
CVE-2017-18593
6.1MEDIUM
What is CVE-2017-18593?
The UpdraftPlus plugin for WordPress, specifically versions prior to 1.13.5, is susceptible to a Cross-Site Scripting (XSS) vulnerability. In certain scenarios, an attacker can manipulate a string that is logged to the log file, allowing for the injection of malicious scripts. If exploited, this vulnerability could enable an attacker to execute arbitrary scripts in the context of the user's browser, potentially leading to session hijacking or other attacks against users accessing the affected site.