Cross-Site Scripting Vulnerability in Responsive Coming Soon Page Plugin for WordPress
CVE-2018-5657
4.8MEDIUM
What is CVE-2018-5657?
A security issue exists in the Responsive Coming Soon Page plugin for WordPress, specifically in version 1.1.18. This vulnerability allows for Cross-Site Scripting (XSS) via the counter_title_icon parameter on the wp-admin/admin.php page. By exploiting this flaw, an attacker can potentially execute arbitrary JavaScript code in the context of the user session, leading to unauthorized actions and data exposure.