CVE-2016-10867: XSS
Published Aug 13, 2019
·Updated
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
Affected Software
1 affected component
Tipsandtricks-hq All In One Wp Security \& Firewall Wordpress<4.0.6
Event History
Aug 13, 2019
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue in the all-in-one-wp-security-and-firewall plugin?
The vulnerability ID for this security issue is CVE-2016-10867.
2
What is the severity level of CVE-2016-10867?
The severity level of CVE-2016-10867 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2016-10867?
The affected software for CVE-2016-10867 is the all-in-one-wp-security-and-firewall plugin before version 4.0.6 for WordPress.
4
What is the CWE identifier for this vulnerability?
The CWE identifier for this vulnerability is CWE-79.
5
How can I fix the XSS vulnerability in the all-in-one-wp-security-and-firewall plugin?
To fix the XSS vulnerability in the all-in-one-wp-security-and-firewall plugin, you should update the plugin to version 4.0.6 or later.