Cross-Site Scripting Vulnerability in Splashing Images Plugin for WordPress
CVE-2018-6194
4.8MEDIUM
What is CVE-2018-6194?
A cross-site scripting vulnerability exists in the admin/partials/wp-splashing-admin-sidebar.php file of the Splashing Images plugin for WordPress prior to version 2.1.1. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML into the application through the 'search' parameter when accessing wp-admin/upload.php, potentially compromising the security of affected installations.