nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18505 CVE-2017-18505
MEDIUMNuclei
BestWebSoft's Twitter < 2.55 - Cross-Site Scripting
Record summary
CVE-2017-18505 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The twitter-plugin plugin before 2.55 for WordPress has XSS.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMBestWebSoft's Twitter < 2.55 - Cross-Site ScriptingCVSS 6.1
The twitter-plugin plugin before 2.55 for WordPress has XSS.
Impact
Authenticated attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
Remediation
Update to version 2.55 or later.
WeaknessesCWE-79
Authorsluisfelipe146
Template tagscvecve2017wordpresswpscanbws-twitterwp-pluginxssauthenticatedbestwebsoftvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:bestwebsoft:twitter_button:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/twitter-plugin/
FOFA: body=/wp-content/plugins/twitter-plugin/
https://wpscan.com/vulnerability/efd816c3-90d4-40bf-850a-0e4c1a756694 https://nvd.nist.gov/vuln/detail/CVE-2017-18505 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18505 https://wordpress.org/plugins/twitter-plugin/#developers
Source: ProjectDiscovery
References
2wordpress.org
https://wordpress.org/plugins/twitter-plugin