Record summary

CVE-2017-18505 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The twitter-plugin plugin before 2.55 for WordPress has XSS.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMBestWebSoft's Twitter < 2.55 - Cross-Site ScriptingCVSS 6.1

The twitter-plugin plugin before 2.55 for WordPress has XSS.

Impact

Authenticated attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.

Remediation

Update to version 2.55 or later.

WeaknessesCWE-79
Authorsluisfelipe146
Template tagscvecve2017wordpresswpscanbws-twitterwp-pluginxssauthenticatedbestwebsoftvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:bestwebsoft:twitter_button:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/twitter-plugin/
FOFA: body=/wp-content/plugins/twitter-plugin/

Source: ProjectDiscovery

References

2