First published: Wed Oct 03 2018(Updated: )
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tribulant Slideshow Gallery | <1.6.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17946 is a vulnerability in the Tribulant Slideshow Gallery plugin before version 1.6.6.1 for WordPress that allows for XSS (Cross-Site Scripting) attacks.
CVE-2018-17946 has a severity of medium with a CVSS score of 6.1.
The Tribulant Slideshow Gallery plugin for WordPress versions up to and excluding 1.6.6.1 is affected by CVE-2018-17946.
To fix CVE-2018-17946, update the Tribulant Slideshow Gallery plugin to version 1.6.6.1 or newer.
CVE-2018-17946 is associated with CWE-79, which is the Common Weakness Enumeration for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').