CVE-2018-18069: XSS
Published Oct 8, 2018
·Updated
processforms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any localefilename parameter (such as localefilenameen) in an authenticated theme-localization.php request to wp-admin/admin.php.
Affected Software
1 affected component
WPML Wpml Wordpress>=1.3.3<=3.6.3
Event History
Oct 8, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-18069.
2
What is the severity rating of CVE-2018-18069?
The severity rating of CVE-2018-18069 is medium (6.1).
3
What software is affected by CVE-2018-18069?
The WPML (aka sitepress-multilingual-cms) plugin through version 3.6.3 for WordPress is affected by CVE-2018-18069.
4
What is the CWE classification of CVE-2018-18069?
The CWE classification of CVE-2018-18069 is CWE-79 (Cross-Site Scripting).
5
How can I fix CVE-2018-18069?
To fix CVE-2018-18069, update the WPML plugin to version 3.6.4 or later.