Cross-Site Scripting Flaw in UserPro Plugin for WordPress
CVE-2018-16285

6.1MEDIUM

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
6 September 2018

Summary

The UserPro plugin for WordPress, up to version 4.9.23, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw occurs when user input is improperly sanitized in the shortcode parameter during the userpro_shortcode_template action in the wp-admin/admin-ajax.php file. Attackers can exploit this vulnerability by crafting malicious shortcode inputs that, when processed by the plugin, could execute arbitrary JavaScript in the context of the user's browser session, potentially compromising sensitive information and user accounts.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.