Cross-Site Scripting Vulnerability in Responsive Coming Soon Page Plugin for WordPress
CVE-2018-5660
4.8MEDIUM
What is CVE-2018-5660?
A cross-site scripting (XSS) vulnerability has been identified in version 1.1.18 of the Responsive Coming Soon Page plugin for WordPress. This issue allows attackers to inject malicious scripts via the 'coming-soon_sub_title' parameter in the wp-admin/admin.php interface. Exploiting this vulnerability could enable unauthorized users to manipulate web pages or steal sensitive information from authenticated users, highlighting the importance of updating plugins and securing WordPress installations.