Cross-Site Scripting in Responsive Coming Soon Page Plugin for WordPress
CVE-2018-5663
4.8MEDIUM
Summary
A vulnerability was identified in the responsive-coming-soon-page plugin (version 1.1.18) designed for WordPress. This flaw allows an attacker to exploit the wp-admin/admin.php button_text_link parameter, leading to potential Cross-Site Scripting (XSS) attacks. Successful exploitation could enable attackers to execute malicious scripts in the context of the user's session, compromising website integrity and user data. Website administrators using this plugin should take necessary security measures to mitigate this risk.
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved