First published: Wed Dec 12 2018(Updated: )
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Codection Import Users From Csv With Meta | =1.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-20101.
The title of this vulnerability is "The codection Import users from CSV with meta plugin before 1.12.1 for WordPress allows XSS via the ..."
The severity of CVE-2018-20101 is medium with a severity value of 6.1.
CVE-2018-20101 affects the Codection Import users from CSV with meta plugin before version 1.12.1 for WordPress.
To fix CVE-2018-20101, update the Codection Import users from CSV with meta plugin to version 1.12.1 or later.