CVE-2018-21014: XSS
Published Sep 9, 2019
·Updated
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
Affected Software
1 affected component
Buddyboss Buddymoss Media Wordpress<=3.2.3
Event History
Sep 9, 2019
CVE Published
via MITRE·12:09 PM
Data Sourced
via MITRE·12:09 PM
Description
Frequently Asked Questions
1
What is CVE-2018-21014?
CVE-2018-21014 is a vulnerability in the buddyboss-media plugin for WordPress that allows for stored XSS attacks.
2
How severe is CVE-2018-21014?
CVE-2018-21014 has a severity rating of medium, with a CVSS score of 5.4.
3
How does CVE-2018-21014 affect WordPress?
CVE-2018-21014 affects WordPress through the buddyboss-media plugin.
4
How can I fix CVE-2018-21014?
To fix CVE-2018-21014, you should update the buddyboss-media plugin to version 3.2.4 or later.
5
Where can I find more information about CVE-2018-21014?
You can find more information about CVE-2018-21014 at the WPScan Vulnerability Database: https://wpvulndb.com/vulnerabilities/9007