CVE-2017-18537: XSS
Published Aug 21, 2019
·Updated
The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
Affected Software
1 affected component
Bestwebsoft Visitors Online Wordpress<1.0.0
Event History
Aug 21, 2019
CVE Published
via MITRE·11:55 AM
Data Sourced
via MITRE·11:55 AM
Description
Frequently Asked Questions
1
What is CVE-2017-18537?
CVE-2017-18537 is a vulnerability in the visitors-online plugin before version 1.0.0 for WordPress, which allows for multiple cross-site scripting (XSS) attacks.
2
How severe is CVE-2017-18537?
CVE-2017-18537 has a severity rating of medium (6.1) based on the Common Vulnerability Scoring System (CVSS).
3
How do I fix CVE-2017-18537?
To fix CVE-2017-18537, you should update the visitors-online plugin to version 1.0.0 or later.
4
Where can I find more information about CVE-2017-18537?
You can find more information about CVE-2017-18537 on the WordPress plugin page: https://wordpress.org/plugins/visitors-online/#developers
5
What is the CWE category for CVE-2017-18537?
CVE-2017-18537 falls under the CWE category 79: Cross-Site Scripting (XSS).