CVE-2018-0602: XSS
Published Jun 26, 2018
·Updated
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Email Subscribers \& Newsletters Project Email Subscribers \& Newsletters Wordpress<3.5.0
Event History
Jun 26, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0602?
CVE-2018-0602 is a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2018-0602?
To fix CVE-2018-0602, update the Email Subscribers & Newsletters plugin to version 3.5.0 or later.
3
What impact can CVE-2018-0602 have on my website?
CVE-2018-0602 can allow remote attackers to inject arbitrary web scripts or HTML into your website.
4
Which versions of Email Subscribers & Newsletters are affected by CVE-2018-0602?
CVE-2018-0602 affects all versions of Email Subscribers & Newsletters prior to 3.5.0.
5
Is CVE-2018-0602 patched?
Yes, CVE-2018-0602 is patched in version 3.5.0 of the Email Subscribers & Newsletters plugin.