CVE-2019-17231: XSS
Published Apr 3, 2020
·Updated
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
Affected Software
1 affected component
Mageewp Onetone Wordpress<=3.0.6
Event History
Apr 3, 2020
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low attack complexity, no privileges required, and user interaction required. Exploitation results in stored XSS, so a user must later view content containing the injected script.
2
Which installations are affected?
The affected component is the Mageewp OneTone WordPress theme through version 3.0.6. The provided data does not identify a configuration prerequisite or mitigation for installations that cannot patch immediately.