CVE-2018-11486: XSS
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11486.
What is the severity of CVE-2018-11486?
The severity of CVE-2018-11486 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2018-11486?
The MULTIDOTS Advance Search for WooCommerce plugin versions up to and including 1.0.9 are affected by CVE-2018-11486.
What is the impact of CVE-2018-11486?
The vulnerability allows a non-authenticated user to inject malicious JavaScript code in the Custom CSS of the plugin settings, leading to potential cross-site scripting (XSS) attacks.
Is there a fix available for CVE-2018-11486?
Yes, it is recommended to update to a version later than 1.0.9 of the MULTIDOTS Advance Search for WooCommerce plugin to mitigate the vulnerability.