CVE-2017-18492: XSS
Published Aug 13, 2019
·Updated
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
Affected Software
1 affected component
BestWebSoft Contact Form to DB<1.5.7
Event History
Aug 13, 2019
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18492?
CVE-2017-18492 is a vulnerability in the contact-form-to-db plugin before version 1.5.7 for WordPress that allows for multiple XSS (Cross-Site Scripting) issues.
2
How severe is CVE-2017-18492?
CVE-2017-18492 has a severity rating of medium with a CVSS score of 6.1.
3
What software is affected by CVE-2017-18492?
The affected software is the contact-form-to-db plugin before version 1.5.7 for WordPress.
4
How can I fix CVE-2017-18492?
To fix CVE-2017-18492, you should update the contact-form-to-db plugin to version 1.5.7 or higher.
5
Where can I find more information about CVE-2017-18492?
You can find more information about CVE-2017-18492 on the official WordPress plugin page: https://wordpress.org/plugins/contact-form-to-db/#developers