First published: Fri Jul 07 2017(Updated: )
Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=3.1.7 | |
WP-Members Membership Plugin | <=3.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2222 is classified as a medium severity cross-site scripting vulnerability.
To mitigate CVE-2017-2222, users should update WP-Members to version 3.1.8 or later.
CVE-2017-2222 affects users of WP-Members versions prior to 3.1.8.
CVE-2017-2222 is a cross-site scripting vulnerability that allows remote attackers to inject arbitrary scripts.
Yes, CVE-2017-2222 can be exploited by unauthenticated remote attackers.