First published: Mon Apr 15 2019(Updated: )
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tribulant Slideshow Gallery | =1.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18019.
The title of the vulnerability is 'XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?'
The severity of CVE-2018-18019 is medium with a CVSS score of 6.1.
The vulnerability manifests as XSS (Cross-Site Scripting) through the Slide[title], Slide[media_file], or Slide[image_url] parameter in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress.
To fix CVE-2018-18019, update the Tribulant Slideshow Gallery plugin to a version that has patched the vulnerability, or consider using an alternative plugin.