First published: Wed Jan 31 2018(Updated: )
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PropertyHive PropertyHive | <1.4.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6465 has a medium severity rating due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2018-6465, update the PropertyHive plugin to version 1.4.15 or later.
CVE-2018-6465 affects the PropertyHive plugin for WordPress versions prior to 1.4.15.
CVE-2018-6465 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Users of the affected versions of the PropertyHive plugin for WordPress may be subject to security risks associated with CVE-2018-6465.