Record summary

CVE-2017-18487 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMAdPush < 1.44 - Cross-Site ScriptingCVSS 6.1

The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.

Impact

Authenticated attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.

Remediation

Update to version 1.44 or later.

WeaknessesCWE-79
Authorsluisfelipe146
Template tagscvecve2017wordpresswpscanwp-pluginxssbws-adpushauthenticatedgoogle_adsense_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:google_adsense_project:google_adsense:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/adsense-plugin/
FOFA: body=/wp-content/plugins/adsense-plugin/

Source: ProjectDiscovery

References

2