First published: Thu Jun 15 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webhammer WP Custom Fields Search | =0.3.28 | |
Webhammer WP Custom Fields Search | =0.3.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9419 is considered a medium severity vulnerability due to its ability to allow remote attackers to execute arbitrary JavaScript.
To fix CVE-2017-9419, update the Webhammer WP Custom Fields Search plugin to the latest version that addresses this vulnerability.
CVE-2017-9419 affects users of the Webhammer WP Custom Fields Search plugin version 0.3.28 on WordPress.
CVE-2017-9419 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2017-9419 can be exploited remotely by attackers to inject malicious JavaScript into the affected WordPress site.