CVE-2017-6818: XSS
Published Mar 12, 2017
·Updated
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
Affected Software
1 affected component
WordPress<=4.7.2
Remediation
Patch Available
Patch Available
Event History
Mar 12, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6818?
The severity of CVE-2017-6818 is considered medium due to the potential risk of cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-6818?
To fix CVE-2017-6818, upgrade WordPress to version 4.7.3 or later.
3
What is CVE-2017-6818?
CVE-2017-6818 is a vulnerability in WordPress that allows for cross-site scripting (XSS) via taxonomy term names before version 4.7.3.
4
Which versions of WordPress are affected by CVE-2017-6818?
CVE-2017-6818 affects WordPress versions prior to 4.7.3.
5
What types of attacks can CVE-2017-6818 lead to?
CVE-2017-6818 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.