CVE-2018-11580: XSS
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11580?
CVE-2018-11580 is an issue discovered in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress, which allows any logged in user to launch Mass Pages/Posts creation with custom content without proper authorization checks.
How does CVE-2018-11580 affect WordPress?
CVE-2018-11580 allows logged in users to launch a denial-of-service (DoS) attack against a WordPress site using the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2.
What is the severity of CVE-2018-11580?
The severity of CVE-2018-11580 is medium, with a severity score of 5.4.
How can I fix CVE-2018-11580?
To fix CVE-2018-11580, it is recommended to update the MULTIDOTS Mass Pages/Posts Creator plugin to a version that includes a fix for the vulnerability.
Where can I find more information about CVE-2018-11580?
More information about CVE-2018-11580 can be found at the following references: [http://labs.threatpress.com/mass-pages-posts-creator/](http://labs.threatpress.com/mass-pages-posts-creator/) and [https://wordpress.org/plugins/mass-pagesposts-creator/#developers](https://wordpress.org/plugins/mass-pagesposts-creator/#developers).