CVE-2018-5672: XSS
Published Jan 13, 2018
·Updated
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php formfield5[label] parameter.
Affected Software
1 affected component
Booking Calendar Project Booking Calendar Wordpress=2.1.7
Event History
Jan 13, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5672?
CVE-2018-5672 has been classified as a medium severity vulnerability.
2
How does CVE-2018-5672 allow for exploitation?
CVE-2018-5672 allows for cross-site scripting (XSS) attacks via the 'form_field5[label]' parameter in the admin interface.
3
Which versions of the booking-calendar plugin are affected by CVE-2018-5672?
CVE-2018-5672 affects version 2.1.7 of the booking-calendar plugin for WordPress.
4
How do I fix CVE-2018-5672?
To fix CVE-2018-5672, update the booking-calendar plugin to a version that addresses this vulnerability.
5
What is the impact of CVE-2018-5672 on WordPress sites?
CVE-2018-5672 can enable attackers to execute arbitrary JavaScript code in the context of an authenticated admin user.