CVE-2017-17451: XSS
Published Dec 7, 2017
·Updated
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.
Affected Software
1 affected component
Wpmailster Wp Mailster Wordpress<1.5.5
Event History
Dec 7, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17451?
CVE-2017-17451 has a medium severity level due to the potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2017-17451?
To fix CVE-2017-17451, update the WP Mailster plugin to version 1.5.5 or later.
3
What type of attack is possible with CVE-2017-17451?
CVE-2017-17451 allows for Cross-Site Scripting (XSS) attacks via the unsubscribe handler.
4
What versions of WP Mailster are affected by CVE-2017-17451?
WP Mailster versions before 1.5.5 are affected by CVE-2017-17451.
5
In which PHP file is CVE-2017-17451 located?
CVE-2017-17451 is located in the view/subscription/unsubscribe2.php file of the WP Mailster plugin.