CVE-2017-18634: Critical severity tagdiv newspaper vulnerability
Published Sep 16, 2019
·Updated
The newspaper theme before 6.7.2 for WordPress has script injection via tdads[header] to admin-ajax.php.
Affected Software
1 affected component
tagDiv Newspaper Wordpress<6.7.2
Event History
Sep 16, 2019
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
Description
Frequently Asked Questions
1
What is CVE-2017-18634?
CVE-2017-18634 is a vulnerability in the newspaper theme before version 6.7.2 for WordPress, which allows script injection through td_ads[header] to admin-ajax.php.
2
How severe is CVE-2017-18634?
CVE-2017-18634 has a severity rating of 9.8, which is considered critical.
3
How can I fix CVE-2017-18634?
To fix CVE-2017-18634, you should update the newspaper theme to version 6.7.2 or later.
4
What is the affected software for CVE-2017-18634?
The affected software for CVE-2017-18634 is the newspaper theme for WordPress, versions before 6.7.2.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-18634?
The CWE ID for CVE-2017-18634 is 74.