CVE-2017-18500: XSS
Published Aug 12, 2019
·Updated
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
Affected Software
1 affected component
Bestwebsoft Social Buttons Pack Wordpress<1.1.1
Event History
Aug 12, 2019
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18500?
CVE-2017-18500 is classified as a high severity vulnerability due to its multiple XSS issues.
2
How do I fix CVE-2017-18500?
To fix CVE-2017-18500, upgrade the BestWebSoft Social Buttons Pack plugin to version 1.1.1 or later.
3
What systems are affected by CVE-2017-18500?
CVE-2017-18500 affects all versions of the BestWebSoft Social Buttons Pack prior to 1.1.1 running on WordPress.
4
What is an XSS vulnerability in the context of CVE-2017-18500?
An XSS vulnerability, like in CVE-2017-18500, allows attackers to inject malicious scripts into web pages viewed by users.
5
Can CVE-2017-18500 be exploited without authentication?
Yes, CVE-2017-18500 can be exploited without authentication, making it critical for all users of the affected plugin.