CVE-2017-13138: XSS
Published Aug 23, 2017
·Updated
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.
Affected Software
1 affected component
Qodeinteractive Bridge Wordpress<=11.1
Event History
Aug 23, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13138?
CVE-2017-13138 is considered a medium severity vulnerability due to the potential for remote code execution via XSS.
2
How do I fix CVE-2017-13138?
To fix CVE-2017-13138, you should update the Bridge theme to version 11.2 or later.
3
Who is affected by CVE-2017-13138?
CVE-2017-13138 affects users of the Bridge theme for WordPress prior to version 11.2.
4
What type of vulnerability is CVE-2017-13138?
CVE-2017-13138 is a DOM-based Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2017-13138 allow attackers to steal data?
Yes, CVE-2017-13138 can allow attackers to inject arbitrary JavaScript and potentially steal sensitive data.