CVE-2018-9172: XSS
Published Apr 1, 2018
·Updated
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
Affected Software
1 affected component
Iptanus Wordpress File Upload Wordpress<4.3.3
Event History
Apr 1, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-9172?
CVE-2018-9172 is a vulnerability in the Iptanus WordPress File Upload plugin before version 4.3.3 for WordPress.
2
What is the severity of CVE-2018-9172?
The severity of CVE-2018-9172 is medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2018-9172?
The affected software for CVE-2018-9172 is the Iptanus WordPress File Upload plugin before version 4.3.3.
4
How can I fix CVE-2018-9172?
To fix CVE-2018-9172, update the Iptanus WordPress File Upload plugin to version 4.3.3 or later.
5
Where can I find more information about CVE-2018-9172?
You can find more information about CVE-2018-9172 on the WordPress plugin page and the Iptanus website.