First published: Mon Mar 26 2018(Updated: )
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Snapcreek Duplicator | =1.2.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7543 is a cross-site scripting (XSS) vulnerability in the SnapCreek Duplicator plugin 1.2.32 for WordPress.
CVE-2018-7543 allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter in installer/build/view.step4.php.
CVE-2018-7543 has a severity rating of medium with a CVSSv3 score of 6.1.
To fix CVE-2018-7543, update the SnapCreek Duplicator plugin to version 1.2.33 or later.
More information about CVE-2018-7543 can be found at the official SnapCreek Duplicator documentation and the Exploit Database.