CVE-2017-18606: XSS
Published Sep 10, 2019
·Updated
The avada theme before 5.1.5 for WordPress has stored XSS.
Affected Software
1 affected component
Theme-fusion Avada Wordpress<5.1.5
Event History
Sep 10, 2019
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18606?
CVE-2017-18606 is a stored Cross-Site Scripting (XSS) vulnerability that can allow attackers to execute arbitrary scripts in the context of a user's browser.
2
How do I fix CVE-2017-18606?
To fix CVE-2017-18606, you should update the Avada theme for WordPress to version 5.1.5 or later.
3
Which versions of the Avada theme are affected by CVE-2017-18606?
CVE-2017-18606 affects all versions of the Avada theme for WordPress prior to 5.1.5.
4
What type of vulnerability is CVE-2017-18606?
CVE-2017-18606 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
5
Is CVE-2017-18606 a critical security issue?
While the severity varies, stored XSS vulnerabilities like CVE-2017-18606 can be considered critical as they can compromise user data and site integrity.