CVE-2017-18495: XSS
Published Aug 13, 2019
·Updated
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
Affected Software
1 affected component
Mediaburst Gravity Forms Wordpress<2.4.0
Event History
Aug 13, 2019
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18495?
The severity of CVE-2017-18495 is classified as medium due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-18495?
To fix CVE-2017-18495, update the Gravity Forms SMS Notifications plugin to version 2.4.0 or later.
3
What type of vulnerability is CVE-2017-18495?
CVE-2017-18495 is an XSS (cross-site scripting) vulnerability affecting the Gravity Forms SMS Notifications plugin.
4
What versions of the software are affected by CVE-2017-18495?
Versions of the Gravity Forms SMS Notifications plugin prior to 2.4.0 are affected by CVE-2017-18495.
5
Is it safe to use older versions of the Gravity Forms SMS Notifications plugin after CVE-2017-18495?
No, using older versions of the Gravity Forms SMS Notifications plugin is not safe due to the XSS vulnerability in CVE-2017-18495.