First published: Mon Oct 07 2019(Updated: )
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Etoilewebdesign Ultimate Faq | <=1.8.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17233 is a vulnerability in the ultimate-faqs plugin for WordPress that allows HTML content injection.
The severity of CVE-2019-17233 is medium.
CVE-2019-17233 affects the ultimate-faqs plugin through version 1.8.24 of the plugin for WordPress.
To fix CVE-2019-17233, you should update the ultimate-faqs plugin to a version higher than 1.8.24.
You can find more information about CVE-2019-17233 on the following references: [link1](https://blog.nintechnet.com/unauthenticated-options-import-vulnerability-in-wordpress-ultimate-faq-plugin/), [link2](https://wordpress.org/plugins/ultimate-faqs/#developers), [link3](https://wpvulndb.com/vulnerabilities/9883).