CVE-2017-18489: XSS
Published Aug 13, 2019
·Updated
The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS.
Affected Software
1 affected component
Mediaburst Contact Form 7 - Clockwork Sms Wordpress<2.4.0
Event History
Aug 13, 2019
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18489?
CVE-2017-18489 is classified as a medium severity vulnerability due to its XSS risk.
2
How do I fix CVE-2017-18489?
To fix CVE-2017-18489, update the contact-form-7-sms-addon plugin to version 2.4.0 or later.
3
Which versions of the plugin are affected by CVE-2017-18489?
Versions of the contact-form-7-sms-addon plugin before 2.4.0 are affected by CVE-2017-18489.
4
What type of vulnerability is CVE-2017-18489?
CVE-2017-18489 is a Cross-Site Scripting (XSS) vulnerability.
5
Is my WordPress site at risk if I use an outdated plugin with CVE-2017-18489?
Yes, if you are using an outdated version of the contact-form-7-sms-addon plugin, your WordPress site is at risk of XSS attacks.