First published: Mon Oct 08 2018(Updated: )
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPML | >=1.3.3<=3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-18069.
The severity rating of CVE-2018-18069 is medium (6.1).
The WPML (aka sitepress-multilingual-cms) plugin through version 3.6.3 for WordPress is affected by CVE-2018-18069.
The CWE classification of CVE-2018-18069 is CWE-79 (Cross-Site Scripting).
To fix CVE-2018-18069, update the WPML plugin to version 3.6.4 or later.