Cross-Site Scripting Vulnerability in WPGlobus Plugin for WordPress
CVE-2018-5364
4.8MEDIUM
What is CVE-2018-5364?
The WPGlobus plugin version 1.9.6 for WordPress contains a Cross-Site Scripting (XSS) vulnerability through the wpglobus_option[browser_redirect][redirect_by_language] parameter found in wp-admin/options.php. This flaw can be exploited by attackers to inject malicious scripts, potentially compromising the security of affected WordPress websites.