First published: Sat Jan 13 2018(Updated: )
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Weblizar Pinterest Feeds | =1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-5653.
The title of the vulnerability is 'An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress.'
The severity of CWE-79 is medium.
The vulnerability occurs via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter.
To fix the vulnerability, you should update to the latest version of the weblizar-pinterest-feeds plugin.