nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18500 CVE-2017-18500
MEDIUMNuclei
Social Buttons Pack by BestWebSof < 1.1.1 - Cross-Site Scripting
Record summary
CVE-2017-18500 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSocial Buttons Pack by BestWebSof < 1.1.1 - Cross-Site ScriptingCVSS 6.1
The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.
Impact
Authenticated attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
Remediation
Update to version 1.1.1 or later.
WeaknessesCWE-79
Authorsluisfelipe146
Template tagscve2017cvewordpresswpscanbws-social-buttonswp-pluginxssauthenticatedbestwebsoftvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:bestwebsoft:social_buttons_pack:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/social-buttons-pack/
FOFA: body=/wp-content/plugins/social-buttons-pack/
https://wpscan.com/vulnerability/efd816c3-90d4-40bf-850a-0e4c1a756694 https://nvd.nist.gov/vuln/detail/CVE-2017-18500 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18500 https://wordpress.org/plugins/social-buttons-pack/#developers
Source: ProjectDiscovery
References
2wordpress.org
https://wordpress.org/plugins/social-buttons-pack