Cross-Site Scripting Vulnerability in WPGlobus Plugin for WordPress
CVE-2018-5362
4.8MEDIUM
What is CVE-2018-5362?
The WPGlobus plugin version 1.9.6 for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability. Attackers can exploit this by manipulating the wpglobus_option[post_type][page] parameter in the wp-admin/options.php file, enabling them to execute arbitrary code or scripts in the context of a user's session. This may lead to unauthorized actions or data exposure. Users of the affected plugin are advised to review their security measures and apply necessary updates or patches.