CVE-2018-5214: XSS
Published Jan 4, 2018
·Updated
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fbfacebookid parameter to wp-admin/profile.php.
Affected Software
1 affected component
Add Link To Facebook Project Add Link To Facebook Wordpress<=2.3
Event History
Jan 4, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5214?
CVE-2018-5214 has a medium severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-5214?
To fix CVE-2018-5214, update the "Add Link to Facebook" plugin to version 2.4 or later.
3
What type of attack is associated with CVE-2018-5214?
CVE-2018-5214 is associated with stored cross-site scripting (XSS) attacks.
4
Which versions of the 'Add Link to Facebook' plugin are affected by CVE-2018-5214?
Versions of the 'Add Link to Facebook' plugin up to and including 2.3 are affected by CVE-2018-5214.
5
Where is the vulnerability located in CVE-2018-5214?
The vulnerability in CVE-2018-5214 is located in the al2fb_facebook_id parameter to wp-admin/profile.php.