Cross Site Scripting Vulnerability in WP ULike by WordPress
CVE-2018-1000508
4.8MEDIUM
Summary
The WP ULike plugin versions 2.8.1 and 3.1 are susceptible to a Cross Site Scripting (XSS) vulnerability located in the Settings screen. This flaw enables unauthorized users to execute harmful scripts, potentially mimicking the access level of an administrator. The vulnerability can be exploited when an admin interacts with the logs page. Mitigation for this issue was implemented in version 3.2.
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved