CVE-2017-18490: XSS
Published Aug 13, 2019
·Updated
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
Affected Software
1 affected component
Bestwebsoft Contact Form Multi Wordpress<1.2.1
Event History
Aug 13, 2019
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18490?
CVE-2017-18490 is a vulnerability found in the contact-form-multi plugin before version 1.2.1 for WordPress, which allows for multiple XSS (Cross-Site Scripting) attacks.
2
What is the severity of CVE-2017-18490?
The severity of CVE-2017-18490 is rated as medium, with a CVSS score of 6.1.
3
How does CVE-2017-18490 affect the contact-form-multi plugin?
CVE-2017-18490 affects the contact-form-multi plugin before version 1.2.1 for WordPress, introducing multiple XSS issues.
4
How can I fix CVE-2017-18490?
To fix CVE-2017-18490, it is recommended to update the contact-form-multi plugin to version 1.2.1 or later.
5
Where can I find more information about CVE-2017-18490?
More information about CVE-2017-18490 can be found at the following link: [link](https://wordpress.org/plugins/contact-form-multi/#developers).