Reflected XSS Vulnerability in Arigato Autoresponder by WordPress
CVE-2018-1002007
4.8MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 3 December 2018
What is CVE-2018-1002007?
A reflected XSS vulnerability exists in the Arigato Autoresponder plugin for WordPress, specifically in the integration-contact-form.html.php file. This security issue allows an attacker with administrative privileges to exploit a POST request variable 'html_id' that could lead to the injection of malicious scripts. Proper validation and sanitization of input are essential to mitigate this risk.
Affected Version(s)
Arigato Autoresponder and Newsletter <= 2.5.1.8