Cross-Site Scripting in WPGlobus Plugin for WordPress
CVE-2018-5366
4.8MEDIUM
What is CVE-2018-5366?
The WPGlobus plugin version 1.9.6 for WordPress is susceptible to cross-site scripting (XSS) due to improper handling of the wpglobus_option[more_languages] parameter in the wp-admin/options.php file. This vulnerability allows an attacker to inject malicious scripts into the web pages viewed by other users, potentially compromising user data and site integrity.