First published: Mon Dec 03 2018(Updated: )
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.
Credit: larry0@me.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kibokolabs Arigato Autoresponder And Newsletter | =2.5.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1002008 is a reflected XSS vulnerability in WordPress Arigato Autoresponder and Newsletter v2.5.1.8.
CVE-2018-1002008 vulnerability has a severity rating of 4.8 (medium).
CVE-2018-1002008 vulnerability affects the Arigato Autoresponder and Newsletter v2.5.1.8 for WordPress.
The impact of CVE-2018-1002008 vulnerability is reflected cross-site scripting (XSS) attacks.
To fix the CVE-2018-1002008 vulnerability, update the Arigato Autoresponder and Newsletter plugin to the latest version.