CVE-2018-7543: XSS
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7543?
CVE-2018-7543 is a cross-site scripting (XSS) vulnerability in the SnapCreek Duplicator plugin 1.2.32 for WordPress.
How does CVE-2018-7543 affect SnapCreek Duplicator?
CVE-2018-7543 allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter in installer/build/view.step4.php.
What is the severity of CVE-2018-7543?
CVE-2018-7543 has a severity rating of medium with a CVSSv3 score of 6.1.
How can I fix CVE-2018-7543?
To fix CVE-2018-7543, update the SnapCreek Duplicator plugin to version 1.2.33 or later.
Where can I find more information about CVE-2018-7543?
More information about CVE-2018-7543 can be found at the official SnapCreek Duplicator documentation and the Exploit Database.