CVE-2017-1000225: XSS
Published Nov 17, 2017
·Updated
Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssididyoumean() could allow unauthenticated attacker to do almost anything an admin can
Affected Software
1 affected component
Relevanssi Relevanssi WordPress=1.14.8
Event History
Nov 17, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000225?
CVE-2017-1000225 is considered a high severity vulnerability due to its potential for reflected XSS attacks.
2
How do I fix CVE-2017-1000225?
To fix CVE-2017-1000225, you should update the Relevanssi Premium plugin to the latest version available.
3
Who is affected by CVE-2017-1000225?
CVE-2017-1000225 affects users of the Relevanssi Premium plugin version 1.14.8 for WordPress.
4
What kind of attack does CVE-2017-1000225 facilitate?
CVE-2017-1000225 facilitates reflected XSS attacks, allowing unauthenticated users to execute scripts on behalf of an admin.
5
Can CVE-2017-1000225 be exploited without authentication?
Yes, CVE-2017-1000225 can be exploited by unauthenticated attackers, making it particularly dangerous.