CVE-2018-5670: XSS
Published Jan 13, 2018
·Updated
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php saleconditions[count][] parameter.
Affected Software
1 affected component
Booking Calendar Project Booking Calendar Wordpress=2.1.7
Event History
Jan 13, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5670?
CVE-2018-5670 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2018-5670?
To fix CVE-2018-5670, update the booking-calendar plugin to the latest version to patch the XSS vulnerability.
3
What versions are affected by CVE-2018-5670?
CVE-2018-5670 specifically affects version 2.1.7 of the booking-calendar plugin for WordPress.
4
What type of attack does CVE-2018-5670 allow?
CVE-2018-5670 allows for Cross-Site Scripting (XSS) attacks via manipulated parameters in the admin interface.
5
Is CVE-2018-5670 easy to exploit?
CVE-2018-5670 can be easily exploited by attackers with access to the wp-admin area, making it a significant risk.