First published: Tue Jun 26 2018(Updated: )
WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in allows unauthorised users to do almost anything an admin can. This attack appear to be exploitable via Admin must visit logs page. This vulnerability appears to have been fixed in 3.2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP ULike | =2.8.1 | |
WP ULike | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000508 is classified as a medium severity vulnerability due to its ability to allow unauthorized users to perform administrative actions.
To fix CVE-2018-1000508, update WP ULike to version 3.2 or later where the vulnerability is patched.
CVE-2018-1000508 affects users of WP ULike versions 2.8.1 and 3.1 running on WordPress.
CVE-2018-1000508 is a Cross Site Scripting (XSS) vulnerability that can allow unauthorized access.
CVE-2018-1000508 requires an admin to visit the logs page for exploitation, but it can lead to significant administrative actions.