CVE-2018-18019: XSS
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[mediafile], or Slide[imageurl] parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-18019.
What is the title of the vulnerability?
The title of the vulnerability is 'XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?'
What is the severity of CVE-2018-18019?
The severity of CVE-2018-18019 is medium with a CVSS score of 6.1.
How does the vulnerability manifest?
The vulnerability manifests as XSS (Cross-Site Scripting) through the Slide[title], Slide[media_file], or Slide[image_url] parameter in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress.
How can I fix CVE-2018-18019?
To fix CVE-2018-18019, update the Tribulant Slideshow Gallery plugin to a version that has patched the vulnerability, or consider using an alternative plugin.